Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 601–675

781 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
Multi-Selectmedium

A system administrator is troubleshooting a network issue where a server cannot reach external websites. The server can ping the default gateway and internal hosts. Which TWO commands should the administrator use to further diagnose the problem? (Choose TWO.)

Select 2 answers
A.nslookup google.com
B.route -n
C.ping 127.0.0.1
D.ifconfig eth0
E.traceroute 8.8.8.8
AnswersA, E

Since gateway and internal pings succeed, routing and local connectivity work, so the fault likely lies in name resolution or external routing. nslookup google.com queries DNS directly, confirming whether the server can resolve external hostnames before any HTTP attempt.

Why this answer

Option A (nslookup google.com) is correct because the server can already reach the gateway and internal hosts, so the next likely failure point is DNS resolution; nslookup queries the configured DNS server to verify that external names like google.com resolve to IP addresses. Option E (traceroute 8.8.8.8) is correct because it traces the hop-by-hop path to an external IP, revealing where packets are dropped (e.g., at the gateway, ISP, or beyond) and distinguishing a routing problem from a DNS problem. Option B (route -n) merely displays the local routing table, which is less useful since the server already pings the gateway and internal hosts, indicating basic routing works.

Option C (ping 127.0.0.1) only tests the local loopback/TCP-IP stack, which is already proven functional by the successful pings to the gateway and internal hosts. Option D (ifconfig eth0) only shows interface configuration (IP, mask, MAC), which is also already validated by the successful internal connectivity.

Exam trap

The trap here is that candidates often choose 'route -n' (B) thinking it will show a missing default route, but since the server can ping the gateway, the default route is present; the real issue is either DNS or a routing problem beyond the first hop, which 'traceroute' (E) specifically addresses.

602
MCQmedium

An Apache web server hosted on a Linux system is unable to connect to a backend database server on port 3306. Based on the exhibit, which action should the administrator take to resolve the issue?

A.Set the httpd_can_network_connect boolean to on.
B.Disable SELinux by setting SELINUX=disabled in /etc/selinux/config.
C.Enable the httpd_enable_home_dirs boolean.
D.Change the SELinux context of the index.html file to httpd_sys_content_t.
AnswerA

SELinux confines httpd with the httpd_t domain, which by default denies outbound TCP connections to database ports. Enabling the httpd_can_network_connect boolean permits exactly that outbound network access, resolving the blocked connection to port 3306 without disabling SELinux enforcement.

Why this answer

The Apache web server cannot connect to the backend database server on port 3306 because SELinux is blocking the outbound network connection. The boolean `httpd_can_network_connect` controls whether the httpd daemon is allowed to initiate outbound TCP connections to remote hosts. Setting this boolean to `on` permits Apache to connect to the database server, resolving the connectivity issue without disabling SELinux entirely.

Exam trap

CompTIA often tests the misconception that SELinux issues are always file-context problems, leading candidates to choose a file-context fix (Option D) when the actual issue is a network connection boolean.

How to eliminate wrong answers

Option B is wrong because disabling SELinux entirely (SELINUX=disabled) removes all SELinux protections, which is an insecure and overly broad solution that violates the principle of least privilege; the correct approach is to enable only the specific boolean needed. Option C is wrong because the `httpd_enable_home_dirs` boolean controls whether httpd can access user home directories (e.g., for UserDir), not outbound network connections to a database server. Option D is wrong because changing the SELinux context of `index.html` to `httpd_sys_content_t` affects file access for serving web content, not the ability of httpd to make outbound TCP connections to a remote database.

603
MCQeasy

A Linux administrator needs to change the permissions of a file to be readable and writable by the owner, readable by the group, and no access for others. Which command accomplishes this?

A.chmod 600 file
B.chmod 664 file
C.chmod 644 file
D.chmod 640 file
AnswerD

chmod 640 sets owner read and write (6), group read only (4), and no permissions for others (0). The octal digits map directly onto the required owner, group and other access, satisfying the stated permission set.

Why this answer

chmod 640 sets owner read+write (6), group read (4), and others no access (0), which matches the requirement exactly. The octal notation maps 4=read, 2=write, 1=execute, so 6=rw, 4=r, 0=none. This is the standard permission set for files that should be private to the owner but readable by a trusted group.

Exam trap

XK0-006 often tests octal-to-symbolic conversion under time pressure — candidates misread 'readable by group' as 'readable by others' and pick 644, or forget the group entirely and pick 600.

How to eliminate wrong answers

Option A is wrong because chmod 600 gives the group no permissions at all, but the requirement states the group must have read access. Option B is wrong because chmod 664 grants others read access (the last 4), violating the 'no access for others' requirement. Option C is wrong because chmod 644 also grants others read access, which the requirement explicitly forbids.

604
MCQhard

A Linux administrator is troubleshooting a system that fails to mount the root filesystem during boot, dropping to an emergency shell. The administrator suspects that a recently added entry in /etc/fstab is incorrect. Which of the following commands should be used to verify the syntax and mountability of all entries in /etc/fstab without actually mounting them?

A.fsck -A
B.findmnt --verify
C.mount -a
D.blkid
AnswerB

The findmnt --verify command checks the syntax of /etc/fstab and other mount configuration files, and verifies that the entries are valid and can be mounted, without actually mounting them. It reports errors and warnings, making it ideal for troubleshooting a suspected incorrect fstab entry that prevents boot.

Why this answer

The findmnt --verify command is designed to validate the syntax and mountability of entries in /etc/fstab and related files without mounting them. It checks for common errors such as invalid device names, duplicate mount points, and unsupported options. This allows the administrator to identify problematic entries before attempting a reboot, avoiding a boot failure.

Other commands either mount the filesystems or perform unrelated checks.

Exam trap

The trap here is confusing mount -a with a verification tool; mount -a actually mounts filesystems and can cause the same failure, while findmnt --verify safely checks without mounting.

605
Multi-Selecteasy

Which of the following commands can be used to display the contents of a file one page at a time? (Choose two.)

Select 2 answers
A.less
B.head
C.cat
D.tail
E.more
AnswersA, E

`less` reads the file lazily and renders it in a scrollable pager, displaying one screenful at a time while allowing forward and backward navigation without loading the whole file into memory. This directly satisfies the requirement to view file contents page by page, unlike `cat`, which dumps everything at once.

Why this answer

Option A, less, is correct because it is a pager that displays a file's contents one screen (page) at a time, allowing forward and backward navigation with keys like Space, b, and q. Option E, more, is also correct because it is a pager that shows file contents one page at a time, advancing with Space and exiting with q, though it traditionally only scrolls forward. Option B, head, is incorrect because it prints only the first 10 lines (by default) and exits, not paging through the file.

Option C, cat, is incorrect because it concatenates and dumps the entire file to standard output at once without pagination. Option D, tail, is incorrect because it prints only the last 10 lines (by default) and exits, not displaying the file page by page.

Exam trap

The trap here is that candidates may confuse `cat` as a pagination tool because it displays file contents, but it lacks any paging or interactive control, while `head` and `tail` are often mistakenly thought to paginate because they show a subset of lines.

606
MCQmedium

A developer is writing a Bash script that needs to parse command-line options with arguments, such as -f filename and -v. Which built-in command should be used to handle these options?

A.getopt
B.getopts
C.case
D.shift
AnswerB

getopts is the shell built-in that parses short options, handling flags and their arguments, and exposes each via OPTARG and OPTIND. It satisfies the requirement to process -f filename and -v without external utilities or manual argument shifting.

Why this answer

getopts is the standard Bash built-in for parsing short options with or without arguments.

607
MCQeasy

An administrator needs to run a backup script every day at 2:00 AM. The script is located at /usr/local/bin/backup.sh and is executable. The administrator considers several methods to schedule this task. Which method should the administrator use to ensure the script runs at exactly 2:00 AM every day without additional configuration overhead?

A.Add the following line to the crontab for root: `0 2 * * * /usr/local/bin/backup.sh`
B.Append the script path to /etc/rc.local file.
C.Place the script in /etc/cron.daily/ directory.
D.Create a systemd timer unit that triggers the script daily at 2:00 AM.
AnswerA

A crontab entry with fields 0 2 * * * runs the script at exactly 02:00 daily. Cron reads the schedule directly, requires no daemon beyond the standard cron service, and adds no wrapper or timer configuration overhead.

Why this answer

The correct method is to add a cron job via crontab because cron is the standard Unix/Linux utility for scheduling tasks at specific times. The syntax `0 2 * * *` precisely defines execution at 2:00 AM daily (minute 0, hour 2, every day, every month, every day of week), and the script path is fully qualified. This approach requires no additional configuration overhead beyond a single crontab entry.

Exam trap

The trap here is that candidates may confuse cron.daily (which runs daily but at a non-configurable time) with a user-crontab entry, or assume systemd timers are simpler than they actually are, overlooking the extra unit files required.

How to eliminate wrong answers

Option B is wrong because /etc/rc.local runs once at system boot, not at a specific daily time like 2:00 AM. Option C is wrong because /etc/cron.daily/ runs once per day but at a system-defined time (typically around 6:25 AM via anacron), not at exactly 2:00 AM, and it cannot be precisely scheduled. Option D is wrong because while a systemd timer can achieve the same result, it requires creating both a service unit and a timer unit, which introduces significantly more configuration overhead compared to a simple crontab entry.

608
MCQmedium

A system administrator wants to ensure that a service starts automatically at boot time using systemd. Which command should be used?

A.systemctl start service
B.systemctl daemon-reload
C.systemctl reenable service
D.systemctl enable service
AnswerD

`systemctl enable service` creates the symbolic links in the systemd unit directories that cause the service to be pulled into the boot transaction, satisfying the requirement that it start automatically at boot. It does not start the unit immediately, unlike `systemctl start`, which affects only the current session.

Why this answer

systemctl enable service creates the necessary symlinks so the service's unit is pulled into the appropriate systemd target at boot, ensuring it starts automatically. This is the standard systemd command for enabling a service at boot time. It does not start the service immediately, but it guarantees it will start on the next boot.

Exam trap

XK0-006 often tests the difference between start (runtime) and enable (boot-time persistence) — candidates pick 'start' because the question mentions 'starts automatically,' conflating immediate start with boot-time enablement.

How to eliminate wrong answers

Option A is wrong because systemctl start service starts the service immediately in the current session but does not configure it to start at boot. Option B is wrong because systemctl daemon-reload reloads unit files after changes but does not enable any service. Option C is wrong because systemctl reenable service is not a valid systemd subcommand — the correct form would be disable followed by enable, or just enable to refresh symlinks.

609
MCQmedium

You are a Linux administrator at a company that runs a web application in Docker containers on a single host. The application consists of a front-end container (nginx) and a back-end container (node.js). Recently, after a system update, the front-end container fails to start with the error: 'Error response from daemon: driver failed programming external connectivity on endpoint frontend: (iptables failed: iptables --wait -t filter -A DOCKER ! -i docker0 -o docker0 -p tcp -d 172.17.0.2 --dport 80 -j ACCEPT: iptables: No chain/target/match by that name)'. Which action should you take to resolve the issue?

A.Restart the Docker daemon with systemctl restart docker
B.Reinstall iptables
C.Change the network driver to macvlan
D.Update the kernel to the latest version
AnswerA

The iptables error shows Docker's DOCKER chain is missing after the update, so the daemon cannot program container port mappings. Restarting the daemon with systemctl rebuilds those iptables chains, restoring the external connectivity the front-end container needs on port 80.

Why this answer

The error indicates that the Docker daemon's iptables rules are corrupted or missing, often caused by a system update that restarted or modified the iptables service. Restarting the Docker daemon with `systemctl restart docker` forces Docker to reinitialize its iptables chains (e.g., DOCKER, DOCKER-USER) and reapply the necessary rules, resolving the connectivity failure.

Exam trap

CompTIA often tests the misconception that iptables itself is broken or needs reinstallation, when the real issue is that Docker's custom iptables chains were lost and need to be recreated by restarting the Docker daemon.

How to eliminate wrong answers

Option B is wrong because reinstalling iptables is unnecessary; the iptables command itself is present and functional (the error is about a missing chain, not a missing binary). Option C is wrong because changing the network driver to macvlan would alter the networking model but does not address the missing iptables chain; the issue is with Docker's default bridge network and its iptables rules. Option D is wrong because updating the kernel is not required; the error stems from a configuration mismatch between Docker and iptables, not a kernel compatibility issue.

610
Multi-Selectmedium

Which TWO commands can be used to display the amount of free and used memory on a Linux system?

Select 2 answers
A.df -h
B.du -sh
C.free -h
D.cat /proc/meminfo
E.iostat
AnswersC, D

The free -h command reads kernel memory statistics and prints them in human-readable units, directly satisfying the requirement to display both free and used RAM and swap. Its -h flag scales values to MiB or GiB, avoiding raw byte counts that obscure quick interpretation.

Why this answer

Option C, free -h, is correct because the free command reads memory statistics from /proc/meminfo and displays total, used, free, shared, buff/cache, and available RAM (and swap) in human-readable units with -h. Option D, cat /proc/meminfo, is correct because /proc/meminfo is the kernel-provided virtual file that exposes detailed memory counters such as MemTotal, MemFree, MemAvailable, Buffers, and Cached, so displaying it directly shows free and used memory. Option A, df -h, is wrong because df reports filesystem disk space usage, not RAM.

Option B, du -sh, is wrong because du estimates file and directory disk usage. Option E, iostat, is wrong because it reports CPU and block-device I/O statistics, not memory usage.

Exam trap

CompTIA often tests the distinction between disk space commands (`df`, `du`) and memory commands (`free`, `/proc/meminfo`), trapping candidates who confuse filesystem usage with RAM usage.

611
MCQmedium

A Linux administrator needs to configure sudo so that members of the group 'webadmins' can run any command as any user without being prompted for a password, but only on the host 'web01'. Which entry should be added to the sudoers file?

A.%webadmins ALL=(ALL) NOPASSWD: ALL
B.%webadmins web01=(ALL) NOPASSWD: ALL
C.webadmins web01=(ALL) NOPASSWD: ALL
D.%webadmins web01=(root) NOPASSWD: /usr/bin/apt
AnswerB

This entry grants the group webadmins (denoted by %) passwordless sudo access to run any command as any user on the host web01. The syntax is correct: user/group, host, runas, and command with NOPASSWD tag. It precisely matches the requirement.

Why this answer

The sudoers syntax allows specifying a group with %, a host, a runas list, and commands. The entry %webadmins web01=(ALL) NOPASSWD: ALL correctly allows group members to run any command as any user on web01 without a password prompt. This is the precise configuration needed.

Exam trap

The trap here is forgetting the % prefix for groups in sudoers or misplacing the host field, which could grant broader access than intended.

612
MCQmedium

A user wants to run a command that will continue running even after the user logs out. Which command should be used?

A.disown command
B.command &
C.bg command
D.nohup command &
AnswerD

nohup makes the process immune to SIGHUP, so it survives the terminal hangup when the user logs out; the trailing & backgrounds it so control returns immediately. Together they satisfy the requirement that the command keep running after logout.

Why this answer

nohup makes the command immune to hangups and runs in the background.

613
Multi-Selectmedium

A system administrator wants to display a list of all currently running processes, including those of other users, with full command lines. Which TWO commands can achieve this? (Select TWO.)

Select 2 answers
A.pstree
B.top
C.ps aux
D.htop
E.ps -ef
AnswersC, E

`ps aux` lists every process on the system, not just the invoking user's, satisfying the requirement to include other users' processes. The `a` flag selects processes from all terminals, `u` adds user-oriented detail, and `x` includes processes without a controlling terminal, while the command column shows full command lines.

Why this answer

Both ps aux (C) and ps -ef (E) are correct because the ps command with these option sets lists every process on the system, not just the current user's, and includes the full command line for each process. ps aux uses BSD-style syntax where 'a' shows processes from all users, 'u' displays user-oriented format, and 'x' includes processes without a controlling terminal, with the COMMAND column showing the full command line. ps -ef uses UNIX-style syntax where '-e' selects all processes and '-f' produces full-format output including UID, PID, PPID, and the complete command line. pstree (A) only shows processes as a hierarchical tree and does not display full command lines with arguments. top (B) and htop (D) are interactive process viewers that by default show only a truncated command column and are not the standard non-interactive way to list all processes with full command lines.

Exam trap

XK0-006 often tests the distinction between interactive monitors (top, htop) and static listing commands (ps) — candidates pick top or htop because they 'show all processes,' but the question requires a command that outputs a full listing with full command lines.

614
MCQmedium

A system administrator wants to ensure that a container can access host devices such as USB drives. Which Docker run option should be used?

A.--device /dev/ttyUSB0
B.--privileged
C.--pid=host
D.--net=host
AnswerA

The `--device` flag maps a specific host device node into the container's namespace, granting direct hardware access without privileged mode. This satisfies the requirement to reach USB drives, whereas `--privileged` would expose all host devices unnecessarily. Passing `/dev/ttyUSB0` gives the container the exact device it needs.

Why this answer

The `--device` flag in Docker allows a container to directly access a specific host device, such as `/dev/ttyUSB0` for a USB drive or serial adapter. This grants the container read/write permissions to the device node without requiring full privileged access, making it the precise and secure option for this requirement.

Exam trap

The trap here is that candidates often choose `--privileged` because they think it is the only way to give a container hardware access, but the exam tests the understanding that `--device` provides granular, secure device access without the broad security implications of full privilege escalation.

How to eliminate wrong answers

Option B is wrong because `--privileged` grants the container all capabilities and full access to all host devices, which is excessive and a security risk; it is not the targeted solution for accessing a specific device like a USB drive. Option C is wrong because `--pid=host` shares the host's PID namespace with the container, allowing the container to see all host processes, but it does not provide any access to host devices. Option D is wrong because `--net=host` makes the container use the host's network stack directly, which affects networking only and has no effect on device access.

615
MCQhard

An administrator needs to generate a self-signed certificate valid for 365 days with a 2048-bit RSA key. Which OpenSSL command correctly creates both the private key and certificate in one step?

A.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
B.openssl x509 -req -in req.pem -signkey key.pem -out cert.pem -days 365
C.openssl ca -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365
D.openssl genrsa -out key.pem 2048 && openssl req -new -x509 -key key.pem -out cert.pem -days 365
AnswerA

Combines key generation and self-signing in a single invocation: -newkey rsa:2048 creates the 2048-bit RSA private key, -x509 emits a self-signed certificate rather than a CSR, -days 365 sets validity, and -nodes omits key encryption.

Why this answer

The command 'openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes' generates a new 2048-bit RSA private key and a self-signed certificate in one step. The -x509 option outputs a self-signed certificate instead of a certificate request, and -nodes ensures the private key is not encrypted. This matches the requirement to create both the private key and certificate simultaneously.

Exam trap

XK0-006 often tests the confusion between generating a self-signed certificate in one step versus using separate commands, and the role of the -nodes flag.

How to eliminate wrong answers

Option B is wrong because 'openssl x509 -req' is used to sign a certificate request, not to generate a new key and self-signed certificate in one step; it requires an existing request and key. Option C is wrong because 'openssl ca' is used to sign certificates as a CA, not for generating self-signed certificates. Option D is wrong because it uses two separate commands: first generating a key with genrsa, then creating a certificate request with 'req -new -x509', which is not a single-step process and lacks the -newkey option to generate the key and certificate together.

616
MCQeasy

Which Dockerfile instruction sets the command to run when the container starts, but allows the user to override it when using docker run?

A.RUN
B.STARTUP
C.ENTRYPOINT
D.CMD
AnswerD

CMD sets the default command executed when the container starts, but it is overridden when arguments are supplied to docker run. ENTRYPOINT, by contrast, is not overridden this way, so CMD matches the stated requirement.

Why this answer

CMD provides defaults for an executing container. If CMD is used, it can be overridden by command-line arguments to docker run. ENTRYPOINT, on the other hand, is not easily overridden without --entrypoint.

617
MCQmedium

An administrator needs to view the last 20 lines of the systemd journal for the 'sshd' service. Which command should be used?

A.systemctl status sshd | tail -20
B.journalctl -u sshd -n 20
C.journalctl -u sshd --since '1 hour ago'
D.journalctl -u sshd -f
AnswerB

The -u flag filters journal entries to the sshd unit, while -n 20 limits output to the most recent 20 lines. Together they satisfy the requirement to view the last 20 journal lines for that specific service.

Why this answer

The command `journalctl -u sshd -n 20` directly queries the systemd journal for entries related to the sshd unit (`-u sshd`) and displays the last 20 lines (`-n 20`). This is the correct and efficient way to view recent journal entries for a specific service. It leverages journalctl's native filtering and tailing capabilities without piping or additional processing.

Exam trap

The trap here is confusing `systemctl status` with `journalctl` for viewing logs, or misinterpreting `-f` as a way to show recent lines rather than follow the log in real-time.

How to eliminate wrong answers

Option A is wrong because `systemctl status sshd` shows the service status summary, not the journal logs, and piping to `tail -20` would only show the last 20 lines of that status output, not the actual journal entries. Option C is wrong because `--since '1 hour ago'` filters by time, not by line count, and would display all entries from the last hour, which may be more or fewer than 20 lines. Option D is wrong because `-f` follows the journal in real-time, displaying new entries as they arrive, rather than showing the last 20 lines and exiting.

618
MCQhard

A system administrator runs the command 'chmod 4755 /usr/local/bin/backup'. What effect does this have on the file?

A.Sets the sticky bit and gives rwxr-xr-x permissions
B.Sets the SUID bit and gives rwxr-xr-x permissions
C.Sets the SGID bit and gives rwxr-xr-x permissions
D.Sets the SUID bit and gives rwxrwxr-x permissions
AnswerB

The leading 4 sets the SUID bit, so the program runs with the file owner's privileges rather than the invoking user's. The remaining 755 grants rwx to the owner and r-x to group and others, matching the octal digits exactly. This satisfies the stem's requirement to interpret chmod 4755 correctly.

Why this answer

The 4 in the first digit sets the SUID bit, so the file runs with the owner's permissions. 755 sets rwxr-xr-x.

619
MCQmedium

An administrator needs to ensure that the SSH service only allows key-based authentication and disables password authentication. Which configuration file and directive should be modified?

A./etc/ssh/sshd_config; PasswordAuthentication yes
B./etc/ssh/sshd_config; PubkeyAuthentication no
C./etc/ssh/ssh_config; PasswordAuthentication no
D./etc/ssh/sshd_config; PasswordAuthentication no
AnswerD

Editing `/etc/ssh/sshd_config` with `PasswordAuthentication no` disables password logins server-side, satisfying the key-only requirement. This directive governs the sshd daemon's authentication methods, so clients offering passwords are rejected while public-key authentication continues to work. Changes require restarting or reloading the SSH service to take effect.

Why this answer

The SSH server configuration file is /etc/ssh/sshd_config, and setting 'PasswordAuthentication no' disables password-based logins, forcing key-based authentication. This directive must be set on the server side (sshd_config), not the client side (ssh_config), to enforce the policy for all incoming SSH connections.

Exam trap

The trap here is confusing the client configuration file (/etc/ssh/ssh_config) with the server configuration file (/etc/ssh/sshd_config), leading candidates to select option C, which would have no effect on the SSH server's authentication behavior.

How to eliminate wrong answers

Option A is wrong because 'PasswordAuthentication yes' would enable password authentication, which is the opposite of the required outcome. Option B is wrong because 'PubkeyAuthentication no' would disable public key authentication, preventing key-based access entirely. Option C is wrong because /etc/ssh/ssh_config is the client-side configuration file; modifying it only affects outgoing SSH connections from that host, not incoming connections to the SSH server.

620
MCQhard

An administrator is configuring a custom kernel module to be loaded automatically at boot for a specialized hardware device. The module is named 'custom_hw'. Which file should be created to ensure the module is loaded at boot?

A./etc/modules-load.d/custom_hw.conf with the line 'custom_hw'
B./etc/sysconfig/modules/custom_hw.modules with modprobe commands
C./etc/modprobe.d/custom_hw.conf with 'options custom_hw param=value'
D./etc/modprobe.d/blacklist.conf with 'blacklist custom_hw'
AnswerA

Writing the module name into /etc/modules-load.d/custom_hw.conf instructs systemd-modules-load.service to load it during early boot, satisfying the automatic-load-at-boot requirement. Unlike /etc/modprobe.d, which only supplies options or blacklists for modules loaded elsewhere, this drop-in directory actively triggers loading, and it works independently of hardware detection.

Why this answer

On modern Linux distributions using systemd, the /etc/modules-load.d/ directory contains .conf files listing kernel modules to load automatically at boot. Each file should contain one module name per line. Option B refers to /etc/sysconfig/modules/, which is used by older distributions but is not the standard for systemd-based systems.

Option C is for setting module parameters, not for loading modules. Option D is for blacklisting modules, preventing them from loading.

621
MCQhard

A system administrator installs a new application that is failing to write to its configuration file in /etc. SELinux is enforcing. Which command would show the relevant SELinux denials?

A.sealert
B.ausearch -m avc -ts recent
C.getenforce
D.audit2why
AnswerB

SELinux denials are logged as AVC messages in the audit log. The ausearch command with -m avc filters specifically for these access vector cache denials, and -ts recent limits output to recent events, directly revealing why the application cannot write to /etc.

Why this answer

The `ausearch -m avc -ts recent` command queries the audit log for AVC (Access Vector Cache) denial messages, which are the specific SELinux denials logged when a process is blocked from accessing a resource. This is the direct way to view recent SELinux denials in an enforcing mode environment, as it filters audit records by message type (AVC) and time range (recent).

Exam trap

CompTIA often tests the distinction between commands that show denials (ausearch) versus commands that interpret or explain denials (audit2why, sealert), leading candidates to pick a tool that requires the denial data as input rather than one that retrieves it directly.

How to eliminate wrong answers

Option A is wrong because `sealert` is a GUI tool that analyzes SELinux denial messages and provides human-readable explanations, but it does not directly show the raw denials from the audit log; it requires the denials to already be present in the audit log or to be run with a specific file. Option C is wrong because `getenforce` only displays the current SELinux mode (Enforcing, Permissive, or Disabled) and does not show any denial logs. Option D is wrong because `audit2why` interprets AVC denial messages from audit logs and explains why access was denied, but it does not show the denials themselves; it requires input from `ausearch` or a log file to function.

622
MCQeasy

A file has permissions -rwxr-x---. The administrator wants to give the group write permission using symbolic mode. Which command is correct?

A.chmod 775 file
B.chmod o+w file
C.chmod u+w file
D.chmod g+w file
AnswerD

g+w adds write permission to the group, leaving other permissions unchanged.

Why this answer

The symbolic mode `g+w` adds write permission to the group owner of the file. The current permissions are `-rwxr-x---`, meaning the group has read and execute (`r-x`) but not write. The `g` stands for group, and `+w` adds write, resulting in `-rwxrwx---`.

Exam trap

The trap here is that candidates may confuse the symbolic mode operators (`u`, `g`, `o`) or incorrectly choose numeric mode (like 775) when the question explicitly requires symbolic mode.

How to eliminate wrong answers

Option A is wrong because `chmod 775` uses numeric (octal) mode, not symbolic mode as specified in the question. Option B is wrong because `o+w` adds write permission for 'others' (the world), not the group. Option C is wrong because `u+w` adds write permission for the file owner (user), not the group.

623
MCQmedium

Refer to the exhibit. The system log is not updating. What is the cause?

A.The syslog file size exceeded 1GB and was rotated.
B.The syslog file permissions are incorrect.
C.The root filesystem is almost full, leaving no space for log growth.
D.rsyslogd was restarted and lost its configuration.
AnswerC

A full root filesystem leaves no free blocks for rsyslog or journald to append entries, so logging silently stalls while other services continue running. The stem's symptom—a system log that has stopped updating—directly matches exhausted disk space on the partition holding /var/log, which is the constraint this option satisfies.

Why this answer

A full root filesystem prevents rsyslogd from writing new entries to /var/log, so the log appears frozen even though the daemon is running. The exhibit (df output showing / at or near 100%) is the giveaway — syslog cannot append when there is no free space, and the kernel may also stop writing to /var/log/messages. Freeing space or moving logs to a separate volume restores logging.

Exam trap

XK0-006 often tests the misconception that a stopped log means the logging daemon crashed or lost its config, when the actual cause is usually environmental — full disk, read-only remount, or SELinux denial — that the exhibit's df output reveals.

How to eliminate wrong answers

Option A is wrong because log rotation is a normal, expected event — rotated files are renamed (e.g., messages-20240101) and a new file is created, so logging continues uninterrupted. Option B is wrong because incorrect permissions would produce permission-denied errors in the daemon's own diagnostics or prevent only specific writers, not silently halt all log updates across the system. Option D is wrong because rsyslogd reads its configuration from /etc/rsyslog.conf at startup; a restart reloads that same file, so it would not lose configuration unless the file itself was deleted or corrupted, which is not indicated.

624
MCQmedium

A Linux administrator wants to harden a server against brute-force attacks. They decide to use fail2ban to monitor SSH authentication failures. After installing and enabling the fail2ban service, they need to verify that the SSH jail is active and correctly configured. Which command should they use to check the current status of the sshd jail?

A.fail2ban-client -v
B.systemctl status fail2ban
C.fail2ban-client status sshd
D.cat /etc/fail2ban/jail.conf
AnswerC

This command queries the fail2ban server for the status of the sshd jail, showing currently banned IPs, total failed attempts, and other statistics. It is the correct way to verify that the jail is active and functioning as intended for SSH protection.

Why this answer

To verify that the sshd jail is active and functioning, the administrator should use fail2ban-client status sshd. This command queries the running fail2ban server and returns details such as the number of failed attempts, banned IPs, and total bans for that specific jail. It is the definitive way to confirm the jail's operational status after configuration.

Exam trap

The trap here is confusing service status with jail status; systemctl status fail2ban only shows if the daemon is running, not whether the sshd jail is correctly monitoring and banning.

625
Drag & Dropmedium

Drag and drop the steps to create a new LVM logical volume in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

LVM requires physical volumes, a volume group, and then a logical volume before formatting and mounting.

626
Multi-Selectmedium

An administrator notices that a critical application server has become extremely slow, and load average has climbed above 40 on a 4-core system. The administrator wants to identify whether the bottleneck is CPU contention or processes stuck in uninterruptible sleep. (Choose two.)

Select 2 answers
A.Run vmstat 1 and observe the r and b columns.
B.Run df -h and check whether any filesystem is at 100 percent utilization.
C.Run lscpu and verify the number of logical CPUs and their current frequency.
D.Run top and examine the load average fields and the per-process state column.
E.Run free -m and compare the total and used memory values.
AnswersA, D

vmstat reports the number of runnable processes in the r column and processes blocked in uninterruptible sleep in the b column. A persistently high r points to CPU saturation, while a high b points to I/O blocking. Sampling every second reveals which condition dominates.

Why this answer

Load average counts both runnable and uninterruptible-sleep tasks, so a high value alone does not reveal the cause. top exposes per-process state letters alongside load averages, and vmstat's r and b columns quantify runnable versus blocked tasks over time. Memory, CPU topology, and filesystem checks do not separate the two candidate bottlenecks.

Exam trap

The trap here is treating a high load average as proof of CPU exhaustion when blocked-on-I/O tasks inflate it just as much as runnable ones.

627
MCQmedium

An administrator needs to check the kernel ring buffer for hardware error messages from the current boot. Which command displays this information?

A.vmstat -f
B.journalctl -k -b 0
C.cat /var/log/boot.log
D.dmesg
AnswerD

`dmesg` reads the kernel ring buffer directly, exposing hardware and driver messages logged during the current boot. This satisfies the stem's requirement to inspect boot-time hardware errors, unlike journal or log-file tools that may aggregate or filter kernel output.

Why this answer

dmesg displays the kernel ring buffer, which includes hardware-related messages from the current boot.

628
MCQmedium

A server is experiencing frequent kernel panics. The administrator wants to capture the crash dump for analysis. Which kernel parameter must be set to enable crash dumps?

A.panic=10
B.kdump_enabled=1
C.irqpoll
D.crashkernel=auto
AnswerD

Setting `crashkernel=auto` reserves memory for the kdump kernel at boot, allowing a secondary kernel to capture the panic dump when the primary one fails. Without this reservation, kdump cannot load, so no vmcore is written. It directly satisfies the requirement to capture the crash dump for analysis.

Why this answer

The `crashkernel=auto` kernel parameter is required to reserve a portion of system memory for the kdump mechanism, which captures a crash dump when a kernel panic occurs. Without this reserved memory, the crash dump cannot be written to disk because the kernel has no safe memory region to operate the dump capture kernel. This parameter is set in the bootloader configuration (e.g., GRUB) and is specific to the kdump service on Linux systems.

Exam trap

The trap here is that candidates confuse the kdump service configuration (e.g., enabling kdump via systemctl) with the required kernel boot parameter `crashkernel`, leading them to select `kdump_enabled=1` as if it were a kernel parameter.

How to eliminate wrong answers

Option A is wrong because `panic=10` sets a timeout in seconds after which the system automatically reboots on a kernel panic, but it does not enable crash dump capture. Option B is wrong because `kdump_enabled=1` is not a valid kernel parameter; the kdump service is controlled via systemd or init scripts, not a kernel boot parameter. Option C is wrong because `irqpoll` is a kernel parameter used to work around interrupt problems by polling IRQs, and it has no role in crash dump capture.

629
MCQmedium

A developer wants to change all occurrences of 'foo' to 'bar' in a configuration file and save the changes in-place. Which sed command should be used?

A.sed -i 's/foo/bar/' file
B.sed -n 's/foo/bar/p' file
C.sed 's/foo/bar/g' file
D.sed -i 's/foo/bar/g' file
AnswerD

The -i flag edits the file in place, while the g suffix replaces every occurrence of foo with bar on each line rather than only the first. This satisfies the requirement to change all matches and save changes directly to the configuration file.

Why this answer

The correct command is sed -i 's/foo/bar/g' file because it combines in-place editing (-i) with the global substitution flag (g), replacing every occurrence of 'foo' on each line. Without -i, changes are only printed to stdout; without g, only the first match per line is replaced.

Exam trap

XK0-006 often tests the combination of -i and g flags — candidates forget that -i alone does not make substitution global, and g alone does not modify the file.

How to eliminate wrong answers

Option A is wrong because it lacks the g flag, so only the first occurrence of 'foo' per line is replaced, not all occurrences. Option B is wrong because -n suppresses automatic printing and the p flag only prints substituted lines, and it does not modify the file in place. Option C is wrong because it lacks -i, so the file is not modified; the result is only written to standard output.

630
MCQhard

An administrator is configuring a Linux firewall to allow incoming SSH (port 22) and HTTPS (port 443) traffic while denying all other incoming traffic. Using iptables, which set of commands achieves this?

A.iptables -P INPUT ACCEPT; iptables -A INPUT -p tcp --dport 22 -j ACCEPT; iptables -A INPUT -p tcp --dport 443 -j ACCEPT
B.iptables -P INPUT DROP; iptables -A INPUT -p tcp --dport 22 -j ACCEPT; iptables -A INPUT -p tcp --dport 443 -j ACCEPT
C.iptables -P FORWARD DROP; iptables -A INPUT -p tcp --dport 22 -j ACCEPT; iptables -A INPUT -p tcp --dport 443 -j ACCEPT
D.iptables -P INPUT ACCEPT; iptables -A INPUT -p tcp --dport 22 -j DROP; iptables -A INPUT -p tcp --dport 443 -j DROP
AnswerB

Setting the INPUT chain's default policy to DROP denies all inbound traffic, then appending ACCEPT rules for TCP ports 22 and 443 permits only SSH and HTTPS. This satisfies the stem's requirement to allow those two services while denying everything else.

Why this answer

It first sets the default policy on the INPUT chain to DROP, which denies all incoming traffic by default. It then adds rules to explicitly ACCEPT incoming TCP traffic on ports 22 (SSH) and 443 (HTTPS), achieving the requirement of allowing only those two services while dropping everything else.

Exam trap

CompTIA often tests the distinction between the INPUT and FORWARD chains, and the trap here is that candidates mistakenly set the default policy on FORWARD instead of INPUT, thinking it controls incoming traffic to the local host.

How to eliminate wrong answers

Option A is wrong because it sets the default INPUT policy to ACCEPT, which allows all incoming traffic by default, then adds ACCEPT rules for ports 22 and 443 — this does not deny other traffic, it just redundantly accepts those ports. Option C is wrong because it sets the default policy on the FORWARD chain to DROP, but the requirement is about incoming traffic to the local system, which is governed by the INPUT chain, not FORWARD; the INPUT chain's default policy remains ACCEPT, so all incoming traffic is still allowed. Option D is wrong because it sets the default INPUT policy to ACCEPT and then adds DROP rules for ports 22 and 443, which would block SSH and HTTPS while allowing all other traffic — the exact opposite of the requirement.

631
Multi-Selectmedium

Which TWO commands can be used to check the kernel version currently running on a system? (Choose two.)

Select 2 answers
A.sysctl kernel.version
B.cat /proc/version
C.lsb_release -a
D.uptime
E.uname -r
AnswersB, E

Contains kernel version string.

Why this answer

The file /proc/version contains the kernel version string, including the version number and compiler information, as maintained by the kernel at boot time. Reading this file with cat displays the exact kernel version currently running on the system.

Exam trap

The trap here is that candidates may confuse distribution release information (lsb_release -a) with kernel version information, or incorrectly assume sysctl has a 'kernel.version' parameter similar to other kernel parameters.

632
MCQhard

An administrator wants to allow the user 'ops' to run only the command '/usr/bin/systemctl restart httpd' via sudo on a specific host 'webserver'. Which /etc/sudoers entry is correct?

A.ops webserver=(root) /usr/bin/systemctl restart httpd
B.ops ALL=(root) /usr/bin/systemctl restart httpd
C.ops webserver=(ALL) /usr/bin/systemctl restart httpd
D.ops webserver=(root) ALL
AnswerA

This entry grants user 'ops' on host 'webserver' permission to run only that exact systemctl restart command as root, with no wildcards or broader command scope. It satisfies the least-privilege constraint by restricting sudo to the single specified command on the specified host.

Why this answer

The sudoers entry format is: user host=(runas) command. To allow user 'ops' to run only the specified command on host 'webserver' as root, the correct entry is 'ops webserver=(root) /usr/bin/systemctl restart httpd'. This restricts both the host and the command, and specifies the runas user as root.

Exam trap

The trap is misplacing the host or runas fields, or using ALL where specificity is required; candidates must match the exact host and command restrictions stated in the question.

How to eliminate wrong answers

Option B is wrong because it uses 'ALL' for the host, meaning the user can run the command on any host, not just 'webserver', violating the specific host requirement. Option C is wrong because it uses '(ALL)' for the runas user, allowing the command to be run as any user, not just root, which is broader than required. Option D is wrong because it allows the user to run ALL commands as root on 'webserver', not just the specified systemctl command, which is far too permissive.

633
MCQeasy

Which file contains the hashed passwords and password aging information for user accounts?

A./etc/shadow
B./etc/gshadow
C./etc/group
D./etc/passwd
AnswerA

/etc/shadow stores hashed passwords plus ageing fields such as last change, minimum, maximum and warning days, readable only by root. This satisfies the requirement for a file holding both hashed passwords and password ageing information.

Why this answer

/etc/shadow stores password hashes and aging fields.

634
MCQeasy

A Docker container needs persistent storage that survives container restarts. Which of the following is the recommended method to achieve this?

A.Use a Docker volume
B.Store data inside the container filesystem
C.Use a bind mount only for configuration files
D.Set the container to always restart
AnswerA

Docker volumes store data outside the container's writable layer, in a host-managed directory, so it persists independently of the container lifecycle. This directly satisfies the requirement that storage survives restarts, unlike bind mounts tied to host paths or data written inside the container, which is destroyed on removal.

Why this answer

Docker volumes are the recommended mechanism for persistent data because they are managed by Docker, stored outside the container's writable layer (typically under /var/lib/docker/volumes), and survive container removal and restarts. They can be named, shared between containers, and backed up or migrated independently of the container lifecycle. This directly satisfies the requirement for storage that persists across restarts.

Exam trap

The trap is thinking that a restart policy or storing data in the container layer provides persistence; candidates must recognize that only volumes (or bind mounts) decouple data from the container lifecycle, and volumes are the recommended default.

How to eliminate wrong answers

Option B is wrong because data written to the container's writable layer is ephemeral — it is destroyed when the container is removed, and even on restart it is tied to that specific container instance, so it is not a reliable persistence method. Option C is wrong because bind mounts are not limited to configuration files; while they can persist data, the question asks for the recommended method, and volumes are preferred for persistent application data due to better portability and management. Option D is wrong because setting a restart policy only controls whether the container restarts after exit; it does nothing to preserve data written inside the container's filesystem.

635
Multi-Selectmedium

A Linux administrator needs to add an ACL entry to grant read permission to a user named 'jdoe' on a file. Which TWO commands can be used to achieve this? (Select TWO).

Select 2 answers
A.setfacl -m u:jdoe:r file
B.setfacl --modify u:jdoe:r file
C.chown jdoe file
D.setfacl -x u:jdoe file
E.chmod u+r file
AnswersA, B

setfacl -m invokes modify mode, and the entry u:jdoe:r adds an ACL granting user jdoe read permission on the file without altering the existing owner, group or other bits. This directly satisfies the requirement to add a read ACL entry for that named user.

Why this answer

Option A, `setfacl -m u:jdoe:r file`, is correct because `-m` is the short form of `--modify`, and `u:jdoe:r` adds or modifies an ACL entry granting user jdoe read permission on the file. Option B, `setfacl --modify u:jdoe:r file`, is correct because it is the long-form equivalent of the same command, performing the identical ACL modification. Option C, `chown jdoe file`, only changes the file's owner and does not create an ACL entry, so it does not grant read permission via ACL.

Option D, `setfacl -x u:jdoe file`, removes an existing ACL entry for jdoe rather than adding one. Option E, `chmod u+r file`, modifies the standard Unix permission bits for the file's owner, not an ACL entry for jdoe.

Exam trap

The trap is confusing ACL modification with ownership change (chown) or standard permission change (chmod), and failing to recognize that -m and --modify are equivalent long/short options for setfacl.

636
MCQmedium

An administrator wants to restrict SSH access to only users in the 'sshusers' group. Which configuration should be added to /etc/ssh/sshd_config?

A.AllowUsers sshusers
B.DenyUsers sshusers
C.AllowGroups sshusers
D.PermitRootLogin no
AnswerC

AllowGroups sshusers restricts SSH logins to members of the sshusers group, satisfying the requirement to limit access by group membership. Unlike AllowUsers, which matches individual accounts, AllowGroups checks the user's supplementary and primary group memberships at authentication, denying all others.

Why this answer

The `AllowGroups` directive in `/etc/ssh/sshd_config` restricts SSH login to users who are members of the specified group. By setting `AllowGroups sshusers`, only users belonging to the 'sshusers' group will be permitted to authenticate via SSH, while all others are denied. This matches the administrator's requirement precisely.

Exam trap

The trap here is that candidates confuse `AllowUsers` (which matches usernames) with `AllowGroups` (which matches group names), leading them to incorrectly select Option A thinking it applies to the group name.

How to eliminate wrong answers

Option A is wrong because `AllowUsers` specifies individual usernames, not groups; `AllowUsers sshusers` would only allow a user literally named 'sshusers', not members of the group. Option B is wrong because `DenyUsers` explicitly denies specific users; `DenyUsers sshusers` would block the user named 'sshusers', which is the opposite of the requirement. Option D is wrong because `PermitRootLogin no` only prevents root from logging in via SSH, but does nothing to restrict access based on group membership.

637
MCQeasy

Which directory in the Linux filesystem contains essential user command binaries that are needed for booting and repairing the system?

A./usr/bin
B./bin
C./sbin
D./opt
AnswerB

/bin holds essential user command binaries required for booting and single-user repair, such as ls, cp and sh. It is distinct from /sbin, which holds system administration binaries, and /usr/bin, which holds non-essential user commands.

Why this answer

/bin contains essential command binaries required for booting and recovery.

638
MCQeasy

A user reports that a shell script fails with a 'Permission denied' error when executed, even though the file has the execute bit set for the owner. The administrator runs `ls -l script.sh` and sees `-rwxr-xr-x`. Which command should the administrator use to determine whether the filesystem is mounted with the `noexec` option?

A.lsattr script.sh
B.getfacl script.sh
C.mount | grep noexec
D.stat script.sh
AnswerC

`mount | grep noexec` lists mounted filesystems and filters for the `noexec` mount option. If the filesystem containing the script is mounted with `noexec`, execution is blocked regardless of file permissions. This command directly reveals whether that option is active, explaining the 'Permission denied' error despite the execute bit being set.

Why this answer

A filesystem mounted with `noexec` prohibits execution of binaries and scripts regardless of file permissions. Checking the mount options with `mount | grep noexec` directly confirms whether this is the cause. Other commands inspect file attributes, ACLs, or metadata, none of which can reveal a filesystem-level execution restriction.

Exam trap

The trap here is focusing on file permissions or attributes when the execute bit is already set, overlooking that a `noexec` mount option can block execution independently of file mode.

639
MCQeasy

A user reports that the 'backup.sh' script runs correctly when launched manually but silently does nothing when executed by cron at 02:00. The script relies on 'tar', which is found at /usr/bin/tar. Which action most directly resolves the failure?

A.Move the script into /etc/cron.daily so it inherits the system environment.
B.Set an explicit PATH variable inside the crontab or use absolute paths for commands in the script.
C.Add 'SHELL=/bin/bash' to the crontab to force an interactive login shell.
D.Change the script's permissions to 777 so cron can execute it.
AnswerB

Cron runs jobs with a minimal environment and a PATH that usually excludes /usr/local/bin and sometimes /usr/bin. When the script calls tar by name, the command is not found and the job fails silently unless output is captured. Defining PATH in the crontab or using absolute paths like /usr/bin/tar ensures the commands resolve, matching the manual-versus-cron discrepancy.

Why this answer

Cron jobs run in a minimal environment where PATH typically contains only /usr/bin:/bin, and shell startup files are not sourced. A script that works interactively can fail under cron because commands are resolved against a different PATH or depend on variables set in a profile. Defining PATH explicitly in the crontab, or referencing binaries by absolute path, restores the resolution the script needs.

Capturing stderr to a log also helps reveal such failures.

Exam trap

The trap here is blaming permissions or the shell, when the classic cron failure is a minimal environment missing PATH entries and profile variables.

640
Multi-Selecteasy

A junior administrator needs to monitor system resource usage on a production server. Which TWO commands should the administrator use to check CPU and memory utilization in real-time? (Choose two.)

Select 2 answers
A.top
B.df
C.uptime
D.lsof
E.free
AnswersA, E

Top displays real-time CPU and memory usage along with processes.

Why this answer

The `top` command provides a real-time, dynamic view of system processes, displaying CPU usage per process, memory utilization, and overall system load. It continuously updates, making it ideal for monitoring resource usage on a production server.

Exam trap

The Linux+ exam often tests the distinction between commands that show real-time resource usage versus those that show static or historical data, and the trap here is that candidates might choose `uptime` thinking it shows CPU utilization, when it only shows load averages.

641
Multi-Selectmedium

A Linux engineer needs to harden SSH access. Which TWO of the following settings should be configured in /etc/ssh/sshd_config to enhance security? (Select TWO.)

Select 2 answers
A.MaxAuthTries 6
B.PasswordAuthentication no
C.Protocol 1
D.PermitRootLogin yes
E.AllowUsers alice bob
AnswersB, E

Disables password logins, reducing risk of brute force.

Why this answer

Option B (PasswordAuthentication no) is correct because disabling password-based authentication forces users to authenticate with SSH key pairs, eliminating brute-force and credential-stuffing attacks against account passwords. Option E (AllowUsers alice bob) is correct because it implements an explicit allowlist, so only the named accounts alice and bob may establish SSH sessions, denying all other valid system users. The remaining options weaken security: MaxAuthTries 6 (A) is too permissive since the default of 3 limits failed attempts more tightly, Protocol 1 (C) enables the obsolete and cryptographically broken SSH-1 protocol, and PermitRootLogin yes (D) allows direct root logins, which should be set to no or prohibit-password.

Exam trap

The trap here is that candidates often confuse 'hardening' with 'increasing limits' (like MaxAuthTries) or 'enabling convenience' (like PermitRootLogin yes), when the correct hardening choices actually restrict or disable weaker authentication methods.

642
MCQeasy

A Linux administrator needs to automate the deployment of a configuration file to fifty servers. The administrator wants to run a single command from a control node that copies the file to all servers in parallel and reports any failures. Which of the following tools is designed specifically for this task?

A.Ansible with an ad-hoc command using the copy module and a hosts inventory.
B.A for loop in a Bash script that calls scp for each hostname in a list.
C.A cron job on each target server that pulls the configuration file from a central web server every hour.
D.rsync run from the control node with a comma-separated list of remote hosts in a single invocation.
AnswerA

Ansible is an agentless automation tool that uses an inventory of hosts and modules such as copy to push files to many servers simultaneously. An ad-hoc command like ansible all -m copy -a 'src=... dest=...' runs against all inventory hosts in parallel and reports per-host results, matching the requirement exactly.

Why this answer

Ansible is purpose-built for agentless automation across many hosts. With an inventory and the copy module, a single ad-hoc command pushes the configuration file to all servers in parallel and returns per-host success or failure, which precisely matches the administrator's need for one command with consolidated reporting.

Exam trap

The trap here is assuming that a shell loop with scp or a single rsync invocation provides parallel fan-out and reporting, when only a configuration management tool like Ansible does so natively.

643
MCQeasy

A system administrator wants to ensure that the /tmp directory is mounted with noexec to prevent code execution from temporary files. Which file should be modified to persist this across reboots?

A./etc/mtab
B./etc/fstab
C./etc/sysconfig/network
D./etc/security/limits.conf
AnswerB

Editing /etc/fstab adds the noexec mount option to the /tmp entry, so systemd applies it automatically at every boot. This satisfies the requirement to persist the setting across reboots, unlike a one-off mount command, which would be lost on restart.

Why this answer

The /etc/fstab file is the system configuration file that defines how disk partitions, block devices, and remote filesystems are mounted at boot time. Adding the noexec mount option to the /tmp entry in /etc/fstab ensures that the /tmp directory is mounted with the noexec flag persistently across reboots, preventing execution of binaries from temporary files.

Exam trap

The trap here is that candidates may confuse /etc/mtab (a runtime snapshot) with /etc/fstab (the persistent configuration file), or think that modifying /etc/mtab will make changes permanent, when in fact it is overwritten on every mount event.

How to eliminate wrong answers

Option A is wrong because /etc/mtab is a dynamically generated file that lists currently mounted filesystems; modifying it does not persist mount options across reboots. Option C is wrong because /etc/sysconfig/network is used for network configuration (e.g., hostname, gateway) and has no role in filesystem mount options. Option D is wrong because /etc/security/limits.conf is used to set per-user resource limits (e.g., file size, number of processes) via PAM, not to control filesystem mount behavior.

644
MCQhard

A production web server intermittently stops responding for about 30 seconds at a time. The administrator runs 'vmstat 1' during an incident and observes the 'wa' column consistently above 80 while 'us' and 'sy' remain low. Which conclusion best describes the bottleneck?

A.The kernel is spending excessive time in system calls, indicating a runaway kernel thread.
B.Processes are blocked waiting on I/O, indicating a storage subsystem bottleneck rather than CPU saturation.
C.User-space applications are consuming all available CPU cycles, indicating a runaway process.
D.The system is swapping heavily because physical memory is exhausted, indicating a memory shortfall.
AnswerB

A high wa value in vmstat means CPUs are idle while waiting for I/O operations to complete. Low us and sy confirm the processors are not the constraint. This points to slow or overloaded storage, such as a failing disk, saturated array, or heavy write load, which matches the intermittent stalls and makes storage the correct diagnosis.

Why this answer

In vmstat output the wa column reports the percentage of CPU time spent idle while outstanding I/O requests exist. When wa is very high while us and sy stay low, the processors are not the limiting factor; the storage path is. The intermittent multi-second stalls are consistent with a storage device or array struggling to service requests, so the administrator should investigate disk health, queue depth, and I/O load.

Exam trap

The trap here is reading high wa as a CPU problem, when it actually measures idle time spent waiting for storage to respond.

645
MCQmedium

A configuration-management playbook run by an administrator must install the nginx package only on hosts whose inventory group is webservers, and must restart the nginx service whenever the package installation changes the system. The administrator is using Ansible. Which pair of task attributes achieves both the conditional execution and the conditional restart?

A.Use when: "inventory_hostname == 'webservers'" on the install task and a notify: directive referencing a handler that restarts nginx.
B.Use when: "'webservers' in group_names" on the install task and a notify: directive referencing a handler that restarts nginx.
C.Use tags: webservers on the install task and a notify: directive referencing a handler that restarts nginx.
D.Use when: "'webservers' in group_names" on the install task and a changed_when: true attribute that restarts nginx.
AnswerB

The when: conditional evaluates the group_names variable, which contains the inventory groups the host belongs to, so the install task runs only on webservers hosts. The notify: directive queues a handler named in the handlers section, and handlers run only when the notifying task reports a changed state. Together they deliver conditional installation plus restart-on-change.

Why this answer

Ansible conditionals evaluate Jinja2 expressions against host facts and magic variables. group_names is a list of the inventory groups containing the current host, so testing membership restricts the install to webservers hosts. The notify: attribute links a task to a handler; handlers are deferred and fire only when the notifying task returns changed, which is exactly the behavior needed to restart nginx solely after a real package change.

Exam trap

The trap here is confusing tags with conditionals; tags gate tasks by command-line selection, while when: evaluates host-specific data during the run.

646
MCQmedium

An administrator notices that a service named 'httpd' is not running. They want to check its current status and, if inactive, start it. Which set of systemctl commands should be used?

A.systemctl list-units httpd; if inactive, systemctl run httpd
B.systemctl show httpd; if inactive, systemctl launch httpd
C.systemctl is-active httpd; if inactive, systemctl enable httpd
D.systemctl status httpd; if inactive, systemctl start httpd
AnswerD

systemctl status httpd reports whether the unit is active, inactive or failed, and systemctl start httpd launches it if inactive. This pairing satisfies the requirement to check current state before conditionally starting the service, using systemd's native unit management.

Why this answer

systemctl status httpd shows the status; if inactive, systemctl start httpd starts it. The other options have incorrect commands or syntax.

647
MCQeasy

A user reports that a Linux workstation fails to boot and displays 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.A filesystem listed in /etc/fstab has errors.
B.A memory module is faulty.
C.The boot loader is missing or corrupted.
D.The root filesystem device is incorrectly specified in the kernel command line.
AnswerD

The kernel cannot locate the root filesystem because the root= parameter points to a wrong or nonexistent device, producing unknown-block(0,0). Correcting the root device specification in the bootloader's kernel command line lets the kernel mount the real root filesystem.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates that the kernel cannot locate the root filesystem device. The most likely cause is that the root filesystem device is incorrectly specified in the kernel command line (e.g., via a bootloader parameter like root=), preventing the kernel from finding the correct block device to mount as root.

Exam trap

The trap here is that candidates often confuse a boot loader issue (which prevents kernel loading) with a kernel command line misconfiguration (which allows the kernel to load but fail to mount root), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because filesystem errors in /etc/fstab would typically cause a failure during the mount of additional filesystems after the root is already mounted, not a kernel panic at boot before the root filesystem is accessed. Option B is wrong because a faulty memory module usually causes random crashes, kernel panics with memory-related errors, or system instability, not a specific VFS root mount failure with unknown-block(0,0). Option C is wrong because a missing or corrupted boot loader would prevent the kernel from being loaded at all, resulting in a blank screen or a 'boot device not found' error, not a kernel panic after the kernel has started executing.

648
MCQhard

A custom application service 'myapp.service' fails to start on a RHEL 8 system with the error: "Failed at step EXEC spawning /usr/local/bin/myapp: Permission denied". The service runs as user 'myapp'. The binary /usr/local/bin/myapp has permissions 755 and is owned by root:root. The user myapp is not in the sudoers. The administrator checks SELinux and finds the binary has the context 'unconfined_u:object_r:usr_t:s0'. The service unit file does not specify any SELinux context. What is the most likely cause of the failure?

A.The user myapp does not have read access to the binary.
B.The SELinux context of the binary is incorrect; it should be bin_t.
C.The binary is located in a directory that is not in the systemd safe path.
D.The binary is not executable by myapp due to file permissions.
AnswerB

The binary has usr_t context, which is not allowed for execution by the service; restoring to bin_t fixes it.

Why this answer

The error occurs because SELinux is enforcing and the binary has the type 'usr_t', which is not allowed to be executed by the service's domain (probably init_t or custom domain). The correct type for executables in /usr/local/bin is 'bin_t'. The solution is to restore the SELinux context to the default for binaries using `restorecon -v /usr/local/bin/myapp` or changing it to bin_t.

Option A is incorrect because permissions allow execution. Option C is unlikely because /usr/local/bin is in PATH. Option D is incorrect as user has execute permission.

649
MCQhard

A Linux administrator is configuring a system to use a centralized authentication service. The requirement is that if the central server is unreachable, users should still be able to log in using cached credentials. Which PAM module should be configured to provide this functionality?

A.pam_ccreds
B.pam_sss with caching enabled in SSSD
C.pam_unix
D.pam_sss
AnswerB

The pam_sss module works with SSSD to authenticate users. When SSSD is configured with caching (e.g., cache_credentials = True), it stores user credentials locally, allowing offline authentication when the central server is unreachable. This is the standard method for providing cached credentials in modern Linux environments.

Why this answer

SSSD with caching enabled provides offline authentication by storing credentials locally. The pam_sss module integrates with SSSD, and when the central server is down, SSSD uses its cache to validate credentials. Other modules like pam_unix only handle local accounts, and pam_ccreds is deprecated.

Exam trap

The trap here is thinking that pam_sss alone provides caching; it requires SSSD to be configured with cache_credentials enabled.

650
MCQmedium

During boot, a Linux system displays a kernel panic with 'VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.Incorrect time configuration in the BIOS
B.Corrupt initramfs missing a necessary kernel module for the root device
C.The /etc/fstab file has an invalid filesystem type for the root partition
D.A defective network cable
AnswerB

The kernel mounts the root filesystem using drivers supplied by the initramfs. If that image is corrupt or omits the storage or filesystem module, the root device cannot be mounted, producing exactly this unknown-block(0,0) panic during boot.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' occurs when the kernel cannot locate or access the root filesystem device. This typically happens because the initramfs (initial RAM filesystem) is corrupt or missing the kernel module (e.g., storage controller driver like ahci, virtio_blk, or LVM/dm modules) needed to detect and mount the root device. Without that module, the kernel has no way to translate the root= parameter into a usable block device, resulting in unknown-block(0,0).

Exam trap

The trap here is confusing post-boot configuration files like /etc/fstab with pre-boot requirements — candidates often assume any filesystem-related error must come from fstab, but fstab is irrelevant before the root filesystem is mounted.

How to eliminate wrong answers

Option A is wrong because an incorrect BIOS time affects clock accuracy and can cause TLS or logging issues, but it has no bearing on the kernel's ability to mount the root filesystem. Option C is wrong because /etc/fstab is processed by userspace after the root filesystem is already mounted — if the root fs can't be mounted, fstab is never read, so an invalid fstab entry cannot produce this panic. Option D is wrong because a defective network cable would only affect network connectivity; a local root filesystem mount does not depend on the network unless using NFS root, which would produce a different error and is not implied here.

651
Multi-Selectmedium

A system is experiencing boot failures. The administrator wants to view kernel messages from the current boot to diagnose the issue. Which two commands can be used to see these messages? (Choose two.)

Select 2 answers
A.journalctl -k
B.cat /proc/kmsg
C.tail -f /var/log/boot.log
D.dmesg
E.vmstat -f
AnswersA, D

`journalctl -k` reads the kernel ring buffer through systemd's journal, filtering entries to kernel-originated messages only. Because the journal persists per-boot metadata, it can restrict output to the current boot, directly satisfying the requirement to inspect kernel messages from the present boot rather than earlier ones.

Why this answer

Option A, journalctl -k, is correct because the -k (--dmesg) filter restricts systemd-journald output to kernel messages only, and by default journalctl shows the current boot's entries, so it displays kernel messages from the present boot. Option D, dmesg, is correct because it reads the kernel ring buffer, which contains the kernel messages generated during the current boot, making it ideal for diagnosing boot failures. Option B, cat /proc/kmsg, is not a good choice because /proc/kmsg is a blocking, consume-once interface intended for a single reader such as klogd or dmesg; reading it directly can steal messages and it does not cleanly present the current boot log.

Option C, tail -f /var/log/boot.log, is incorrect because boot.log contains service startup output from the init/boot process, not kernel messages, and it may not exist on systemd systems. Option E, vmstat -f, is incorrect because it reports the number of forks since boot, which is unrelated to viewing kernel messages.

Exam trap

The trap here is that candidates confuse `dmesg` with `cat /proc/kmsg` or think `boot.log` contains kernel messages, when in fact `dmesg` and `journalctl -k` are the standard tools for viewing kernel ring buffer output from the current boot.

652
MCQhard

A Linux administrator is troubleshooting a server that randomly drops SSH connections. The administrator suspects a network interface is experiencing errors or discards. Which command should be used to display detailed error and discard statistics for a specific network interface?

A.ip -s link show eth0
B.netstat -i
C.ifconfig eth0
D.ethtool -S eth0
AnswerA

The ip -s link show command displays interface statistics, including RX/TX errors, dropped packets, and overruns. By specifying eth0, the administrator can see detailed counters that indicate whether the interface is experiencing errors or discards, which could explain dropped SSH sessions. This directly addresses the need to inspect error and discard statistics for a specific interface.

Why this answer

The administrator needs error and discard statistics for a specific interface. ip -s link show eth0 provides a standardized, detailed view of RX/TX errors, dropped packets, and overruns. While other tools may show some statistics, ip is the modern, reliable choice and directly meets the requirement.

Exam trap

The trap here is assuming that any interface statistics command will provide the same level of detail, when older or driver-specific tools may lack the necessary error and discard counters.

653
MCQhard

An application is being denied access to a file due to SELinux. Which command can be used to temporarily set the SELinux context of the file to match the expected type for the application?

A.chcon -t httpd_sys_content_t /var/www/html/index.html
B.setenforce 0
C.restorecon -v /var/www/html/index.html
D.semanage fcontext -a -t httpd_sys_content_t /var/www/html
AnswerA

`chcon -t httpd_sys_content_t` directly relabels the file's SELinux type to `httpd_sys_content_t`, satisfying the stem's requirement to temporarily set a context matching the application's expected type. Unlike `semanage fcontext`, which writes persistent mapping rules, `chcon` changes only the live label, so the change is lost on relabelling.

Why this answer

The `chcon` command is used to temporarily change the SELinux context of a file without modifying the SELinux policy. By specifying `-t httpd_sys_content_t`, the file's type is set to the expected type for Apache (httpd) to access it, resolving the denial immediately. This change is not persistent across file system relabeling, making it ideal for temporary troubleshooting.

Exam trap

The trap here is that candidates confuse `chcon` (temporary, immediate change) with `restorecon` (reverts to policy default) or `semanage fcontext` (persistent policy rule that requires an extra step to apply), leading them to pick an option that either disables SELinux or does not immediately fix the file context.

How to eliminate wrong answers

Option B is wrong because `setenforce 0` disables SELinux entirely (sets it to permissive mode), which is a drastic measure that bypasses all SELinux protections rather than fixing the specific file context issue. Option C is wrong because `restorecon -v` restores the file's SELinux context to the default policy-defined type, which would only help if the current context is incorrect and the default matches the expected type; it does not set a custom type like `httpd_sys_content_t`. Option D is wrong because `semanage fcontext -a -t httpd_sys_content_t /var/www/html` adds a persistent rule to the SELinux policy for the file, but it does not immediately apply the context to the file; a subsequent `restorecon` or `touch` is required to activate the change, so it is not a temporary fix.

654
Multi-Selectmedium

A Linux administrator needs to configure sudo access for members of the 'wheel' group to run any command. Which two steps are required? (Choose TWO.)

Select 2 answers
A.Uncomment the line '%wheel ALL=(ALL) ALL' in /etc/sudoers using visudo
B.Set the setuid bit on /usr/bin/sudo
C.Run 'sudo visudo -c' to check syntax
D.Add users to the 'wheel' group using usermod -aG wheel username
E.Edit /etc/ssh/sshd_config to allow wheel group
AnswersA, D

Uncommenting `%wheel ALL=(ALL) ALL` in /etc/sudoers grants the wheel group password-prompted sudo rights to run any command as any user, satisfying the "any command" requirement. Editing via visudo validates syntax before saving, preventing a corrupted sudoers file that would lock out all sudo access.

Why this answer

Option A is correct because the '%wheel ALL=(ALL) ALL' entry in /etc/sudoers is the standard sudoers rule that grants every member of the wheel group permission to run any command as any user on any host, and it must be uncommented (edited with visudo to preserve syntax safety and file locking). Option D is correct because users only receive that sudo privilege if they are actually members of the wheel group, so adding them with 'usermod -aG wheel username' (the -a avoids removing existing supplementary groups) is a required step. Option B is wrong because /usr/bin/sudo is already installed with the setuid root bit by the package; manually setting it is unnecessary and not part of granting wheel sudo rights.

Option C is wrong because 'visudo -c' only validates sudoers syntax — it is a verification step, not a required configuration step. Option E is wrong because /etc/ssh/sshd_config controls SSH login behavior, not sudo authorization, and has nothing to do with granting wheel members command execution rights.

Exam trap

The trap here is that candidates confuse the setuid bit on sudo (which is already set) with a configuration step, or think that editing SSH config or running syntax checks alone grants sudo access, when in fact both the sudoers rule and group membership are required.

655
Multi-Selecthard

A security audit identified that the /tmp directory is world-writable. Which THREE steps should be taken to secure /tmp on a Linux system? (Select THREE.)

Select 3 answers
A.Set the sticky bit on /tmp
B.Remove world-writable permission from /tmp
C.Mount /tmp with the nosuid option
D.Mount /tmp with the noexec option
E.Mount /tmp with the exec option
AnswersA, C, D

The sticky bit restricts deletion or renaming of files within /tmp so only each file's owner, the directory owner or root may remove them. This mitigates the world-writable risk without removing write access that applications legitimately require.

Why this answer

Option A is correct because setting the sticky bit (chmod +t /tmp, shown as the t in drwxrwxrwt) ensures that only the owner of a file, the directory owner, or root can delete or rename files within /tmp, preventing users from tampering with each other's files in this shared world-writable directory. Option C is correct because mounting /tmp with nosuid prevents setuid/setgid bits on binaries placed in /tmp from being honored, blocking a common privilege-escalation vector in a world-writable location. Option D is correct because mounting /tmp with noexec prevents execution of binaries from /tmp, further reducing the attack surface for malware or exploit payloads dropped there.

Option B is not appropriate because /tmp must remain world-writable for applications and users to create temporary files; removing world-writable permission would break normal system operation. Option E is incorrect because explicitly allowing exec on /tmp is the opposite of the hardening measure needed and would permit execution of untrusted binaries.

Exam trap

The trap here is that candidates may think removing world-writable permissions is the correct fix, but that would break system functionality; instead, the sticky bit and mount options are the proper hardening steps without breaking compatibility.

656
MCQhard

A Linux administrator is troubleshooting a server that fails to mount a filesystem listed in /etc/fstab during boot, causing the system to drop into emergency mode. The administrator wants to prevent the system from entering emergency mode if this particular mount fails, while still attempting to mount it. Which fstab option should be added to the mount entry?

A.nouser
B.auto
C.nofail
D.defaults
AnswerC

The nofail option tells systemd that the mount is not required for boot. If the device is missing or the mount fails, the boot process continues without entering emergency mode. This directly addresses the requirement to avoid emergency mode while still attempting the mount.

Why this answer

The nofail option in /etc/fstab instructs systemd to ignore mount failures for that entry, allowing the boot to proceed even if the device is unavailable. This prevents the system from dropping into emergency mode. The other options either do not affect error handling or are already implied by defaults, so they do not provide the needed resilience.

Exam trap

The trap here is confusing nofail with other mount options like auto or defaults, which do not prevent emergency mode on mount failure.

657
MCQmedium

A Linux server's root filesystem was accidentally filled to 100% capacity by runaway application logs. After the administrator deletes several large log files with rm, df -h still reports the filesystem at 100% usage. Which command should the administrator use to identify the process that is holding these deleted files open?

A.df -i
B.fuser -m /
C.du -sh /var/log
D.lsof +L1
AnswerD

lsof +L1 lists all open files that have a link count less than 1, which indicates deleted files still held open by a process. This directly identifies the process preventing space from being reclaimed, allowing the administrator to restart or kill it to free the space. It is the precise tool for this scenario.

Why this answer

The correct tool is lsof +L1, which specifically lists open files with a link count less than one, indicating deleted files still held open by a process. In this scenario, the deleted log files are still consuming disk space because a process has them open. Identifying and restarting that process will release the space, resolving the 100% usage.

Exam trap

The trap here is assuming that deleting a file immediately frees disk space, when in fact the space remains allocated until all file descriptors referencing it are closed.

658
Multi-Selecthard

Which THREE tools are commonly used for configuration management?

Select 3 answers
A.Chef
B.Ansible
C.Puppet
D.Kubernetes
E.Docker
AnswersA, B, C

Chef enforces desired state through declarative recipes and cookbooks, converging nodes via its agent and Chef Server. This satisfies the stem's configuration management requirement by automating consistent package, file and service configuration across fleets, rather than merely provisioning infrastructure or orchestrating containers like other tools.

Why this answer

Chef (A) is a widely used configuration management tool that uses cookbooks and recipes to define and enforce the desired state of servers, making it a correct choice. Ansible (B) is a common agentless configuration management tool that applies playbooks over SSH to configure systems, so it is also correct. Puppet (C) is another established configuration management tool that uses a declarative manifest language and a master-agent architecture to manage configuration drift, confirming it as correct.

Kubernetes (D) is a container orchestration platform rather than a configuration management tool, and Docker (E) is a containerization platform, so neither belongs in this category.

Exam trap

CompTIA often tests the distinction between configuration management (Chef, Ansible, Puppet) and container/orchestration tools (Docker, Kubernetes), leading candidates to mistakenly select Kubernetes or Docker as configuration management tools.

659
MCQeasy

A Linux administrator is troubleshooting a service that fails to start. They want to view the most recent log entries for that service using systemd's journal. Which command should they use?

A.dmesg | grep servicename
B.systemctl status servicename
C.journalctl -u servicename
D.tail -f /var/log/messages
AnswerC

journalctl -u filters the journal by the specified systemd unit, showing all log entries for that service. This is the most direct way to see why the service failed. It includes messages from the service's startup, errors, and dependencies, making it ideal for troubleshooting a failed start.

Why this answer

The journalctl -u command filters the systemd journal by unit, providing all log messages for that service. This is the correct tool to diagnose why a service fails to start, as it captures the service's standard output, error messages, and systemd's own messages about the unit.

Exam trap

The trap here is confusing systemctl status, which gives a summary, with journalctl -u, which provides the full log history for the service.

660
MCQhard

An administrator needs to generate a self-signed certificate and private key for an internal web server. Which OpenSSL command creates both in one step?

A.openssl ca -in req.pem -out cert.pem
B.openssl genrsa -out key.pem 2048 && openssl req -new -x509 -key key.pem -out cert.pem -days 365
C.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
D.openssl x509 -req -in req.pem -signkey key.pem -out cert.pem
AnswerC

The `-x509` flag makes `req` emit a self-signed certificate rather than a certificate signing request, while `-newkey rsa:2048` generates the private key alongside it. `-keyout` and `-out` write both files in a single invocation, satisfying the requirement to create certificate and key together.

Why this answer

The `openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes` command generates a new RSA private key and a self-signed X.509 certificate in a single step. The `-x509` flag outputs a self-signed certificate instead of a CSR, `-newkey` creates the key pair, and `-nodes` prevents encryption of the private key, which is typical for an internal web server that must start without manual passphrase entry.

Exam trap

The trap here is that candidates may think Option B is correct because it technically works, but the question explicitly asks for a command that creates both 'in one step', meaning a single OpenSSL command, not a shell pipeline of two separate commands.

How to eliminate wrong answers

Option A is wrong because `openssl ca` is used to sign a certificate request (CSR) with a CA certificate, not to generate a self-signed certificate and private key together; it requires an existing CA setup and a pre-generated CSR. Option B is wrong because while it does produce a self-signed certificate and key, it uses two separate commands (`genrsa` then `req`) chained with `&&`, which is not a single OpenSSL command as the question asks for 'one step'. Option D is wrong because `openssl x509 -req` signs a CSR using an existing key (`-signkey`), but it does not generate a new private key; it requires a pre-existing CSR and key file, so it cannot create both in one step.

661
MCQmedium

An administrator wants to find all files in the current directory tree that are larger than 100 MB and have the .log extension. Which find command will accomplish this?

A.find . -name '*.log' -size +100M
B.find . -name '*.log' -size +100MB
C.find . -name '*.log' -size -100M
D.find . -type f -size +100M
AnswerA

The `-size +100M` predicate filters on file size in mebibytes, while `-name '*.log'` matches the extension, and the starting point `.` recurses the current directory tree. Both constraints from the stem are satisfied in a single pass, with no piping required.

Why this answer

Find . -name '*.log' -size +100M. This command searches recursively from the current directory (.) for files with names matching '*.log' (-name '*.log') and with size greater than 100 MB (-size +100M). Option B is incorrect because the size syntax +100MB is wrong; the correct suffix is M for megabytes.

Option C uses -size -100M which finds files smaller than 100 MB. Option D uses -type f (files only) but does not filter by .log extension, so it would include all files larger than 100 MB regardless of extension.

662
MCQhard

An administrator configures /etc/ssh/sshd_config with the following settings: PermitRootLogin no, PasswordAuthentication no, AllowUsers alice bob, MaxAuthTries 2. After restarting sshd, which of the following is true?

A.User charlie can log in using a public key.
B.User bob can log in using a public key.
C.User alice can log in using a password.
D.Root can log in using a valid password.
AnswerB

PasswordAuthentication no forces public-key authentication, and AllowUsers alice bob permits bob, so bob can log in with a public key. PermitRootLogin no blocks root, and MaxAuthTries 2 limits attempts, but neither prevents bob's key-based login.

Why this answer

PasswordAuthentication no disables password logins, so public key authentication is required. PermitRootLogin no prevents root login entirely. AllowUsers restricts to alice and bob only.

MaxAuthTries 2 limits authentication attempts. So root cannot log in even with keys, and alice/bob must use keys.

663
MCQmedium

A Linux server has a single disk /dev/sda with LVM. The root logical volume is nearly full and the administrator adds a new disk /dev/sdb to extend it. After creating a physical volume on /dev/sdb and adding it to the volume group, which command should be used to extend the root logical volume and its filesystem in one step?

A.vgextend vg0 /dev/sdb && lvcreate -l +100%FREE -n root vg0
B.lvresize -L +10G /dev/vg0/root && resize2fs /dev/vg0/root
C.pvresize /dev/sdb && lvextend -L +10G /dev/vg0/root
D.lvextend -r -l +100%FREE /dev/vg0/root
AnswerD

The -r (or --resizefs) option to lvextend resizes the underlying filesystem together with the logical volume, so the root LV and its filesystem are extended in a single command. Using -l +100%FREE allocates all remaining free extents in the volume group. This is the correct and efficient way to grow the LV and filesystem without a separate resize2fs or xfs_growfs step.

Why this answer

Extending an LVM logical volume and its filesystem in one step is done with lvextend -r (or --resizefs). The -r flag automatically calls the appropriate filesystem resize tool (resize2fs for ext4, xfs_growfs for XFS) after growing the LV. Using -l +100%FREE allocates all remaining extents in the volume group.

This avoids a separate manual resize step and works for both ext4 and XFS, making it the most reliable choice.

Exam trap

The trap here is assuming that lvextend always resizes the filesystem automatically, when in fact the -r option is required to do so.

664
MCQmedium

A Linux administrator is automating user account creation. The script reads a list of usernames from a file and creates each account. The administrator wants the script to continue processing remaining users even if one useradd command fails due to a duplicate username. Which Bash construct should be used to run useradd and handle the failure without aborting the script?

A.set -e; useradd "$user"
B.useradd "$user" || echo "Failed to add $user" >&2
C.useradd "$user" && echo "Failed to add $user" >&2
D.useradd "$user" | echo "Failed to add $user" >&2
AnswerB

The || operator runs the right-hand command only when the left-hand command returns a non-zero exit status. This allows the script to log the failure for a duplicate username and continue with the next iteration, which matches the requirement to keep processing remaining users without aborting the entire script.

Why this answer

The || control operator provides a concise way to execute a fallback command only when the preceding command fails. By pairing useradd with a failure branch, the script can report the duplicate username and proceed to the next iteration, satisfying the requirement to continue processing the remaining users.

Exam trap

The trap here is confusing the short-circuit behavior of && and ||, since && fires on success while || fires on failure.

665
MCQeasy

Which command is used to display the contents of a compressed log file without decompressing it?

A.head
B.zcat
C.cat
D.less
AnswerB

`zcat` streams decompressed data from gzip-compressed files straight to standard output, leaving the original archive untouched on disk. This satisfies the stem's constraint of reading a compressed log's contents without decompressing it, since no extracted file is written. It also handles `.gz` logs directly, unlike `cat`, which would emit raw binary.

Why this answer

zcat (equivalent to gzip -dc) reads a gzip-compressed file and writes the decompressed content to standard output without modifying the original file. It is the standard tool for viewing .gz log files in place, and it can be piped to less or grep for further processing.

Exam trap

XK0-006 often tests whether candidates know that cat and head do not decompress — the trap is assuming any file-reading command handles gzip transparently.

How to eliminate wrong answers

Option A is wrong because head reads the first lines of a file as-is; on a gzip file it would output binary garbage, not decompressed text. Option C is wrong because cat concatenates and prints raw file bytes — again producing binary output on a compressed file. Option D is wrong because less, while it can display text, does not decompress gzip files by default (though less can be configured with LESSOPEN to pipe through gzip, that is not its native behavior).

666
Multi-Selecteasy

A user wants to view the contents of a text file one page at a time. Which two commands can be used? (Choose two.)

Select 2 answers
A.less
B.cat
C.tail
D.head
E.more
AnswersA, E

less displays file contents one screenful at a time, supporting forward and backward scrolling plus in-page searching. It satisfies the paging requirement directly, unlike cat, which dumps the entire file to standard output without pagination.

Why this answer

Both less (A) and more (E) are paging utilities that display a text file one screenful at a time and pause for the user to scroll, which directly matches the requirement. less is the more capable pager, supporting both forward and backward navigation plus searching, while more provides basic forward paging and is available on virtually all Unix-like systems. The other commands do not page output: cat (B) dumps the entire file to standard output at once, and tail (C) and head (D) only print the last or first lines (10 by default) respectively, so none of them let the user view the file page by page.

667
Drag & Dropmedium

Drag and drop the steps to configure SELinux to allow a custom web application to listen on port 8080 in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

SELinux requires adding the port to the appropriate context before the service can listen.

668
MCQhard

A senior administrator is troubleshooting a shell script that fails to execute properly. The script starts with #!/bin/bash and has execute permissions. Which of the following could cause the script to fail to run when invoked as ./script.sh?

A.The shebang line is not on the first line.
B.The script contains carriage return characters (\r).
C.The script uses #!/bin/sh instead of bash.
D.The script starts with a byte order mark (BOM).
AnswerB

Can cause 'No such file or directory'.

Why this answer

Carriage return characters (\r) are a common issue when scripts are edited on Windows and then transferred to Linux. The shebang line #!/bin/bash expects a Unix-style line ending (LF), but \r characters cause the shell to interpret the command interpreter as '/bin/bash\r', which is not a valid executable path. This results in a 'No such file or directory' error when the script is invoked as ./script.sh, even though permissions are correct.

Exam trap

The trap here is that candidates may think the shebang line must be on the first line (Option A) is the issue, but CompTIA tests the subtle Windows line-ending problem (\r) that causes the interpreter path to be invalid, which is a common real-world pitfall when scripts are edited in Windows environments and transferred to Linux.

How to eliminate wrong answers

Option A is wrong because the shebang line must be on the first line of the script; if it is not, the script will still execute but will be interpreted by the default shell (usually /bin/sh) rather than bash, which may cause different behavior but not necessarily a failure to run. Option C is wrong because using #!/bin/sh instead of #!/bin/bash does not cause the script to fail to run; it simply invokes the system's default Bourne shell, which may lack some bash-specific features but will still execute the script if it is compatible. Option D is wrong because a byte order mark (BOM) at the start of the script is a Unicode encoding artifact that can cause the shebang line to be misinterpreted, but it is less common than carriage return issues and typically results in a 'bad interpreter' error similar to \r, but the question specifically tests the more frequent Windows-to-Linux line-ending problem.

669
MCQmedium

A Linux administrator needs a service to be started automatically at boot and then started immediately without rebooting. The service unit file is located at /etc/systemd/system/myapp.service. Which command should the administrator run to accomplish both tasks?

A.systemctl start myapp.service && systemctl daemon-reload
B.systemctl link /etc/systemd/system/myapp.service
C.systemctl enable myapp.service && systemctl restart myapp.service
D.systemctl enable --now myapp.service
AnswerD

This command both enables the unit to start at boot by creating the appropriate symlinks and starts it immediately. The --now flag is the standard systemd way to combine enable and start in one step. It satisfies the requirement to start automatically at boot and to start the service right away without rebooting.

Why this answer

The correct command is systemctl enable --now myapp.service. The enable subcommand sets up the unit to start at boot, and --now starts it immediately. This single command satisfies both requirements without requiring a reboot or separate commands.

Other options either omit enabling, omit starting, or use commands that do not achieve both goals.

Exam trap

The trap here is assuming that starting a service also enables it for boot, or that daemon-reload is needed after enabling a unit.

670
MCQmedium

A system administrator is troubleshooting a service that fails to start with the error 'Unit failed to load: Invalid argument'. The service file is located in /etc/systemd/system. What is the most likely cause?

A.The service binary is missing
B.The service file has a syntax error
C.The service requires a dependency that is not installed
D.The service is masked
AnswerB

systemd parses unit files strictly; an invalid directive, malformed section header or bad value causes the loader to reject the unit with 'Invalid argument' before execution. A syntax error in the file under /etc/systemd/system therefore prevents the unit from loading at all, matching the reported error.

Why this answer

The error 'Unit failed to load: Invalid argument' in systemd indicates that the unit file parser encountered a directive or value it could not interpret. This is most commonly caused by a syntax error in the service file, such as a misspelled key, an invalid setting, or a malformed line. Systemd validates the file structure against its grammar; any deviation triggers this specific error.

Exam trap

The trap here is that candidates often confuse runtime errors (like missing binaries or dependencies) with parsing errors, but the specific 'Invalid argument' message points directly to a syntax or configuration issue within the unit file itself.

How to eliminate wrong answers

Option A is wrong because a missing service binary would cause a different error, such as 'Exec format error' or 'Unit not found' when trying to execute the binary, not a parsing failure. Option C is wrong because a missing dependency typically results in 'dependency failed' or 'unit not found' errors, not an 'Invalid argument' syntax error. Option D is wrong because a masked service produces 'Unit is masked' or 'Failed to start unit: Unit is masked' errors, not a syntax-level parsing failure.

671
MCQeasy

An administrator runs the command `ls -l /data/file.txt` and sees the output: `-rw-r-----+ 1 root project 1024 Mar 15 10:00 file.txt`. The administrator wants to view the current ACL entries on this file. Which command should be used?

A.getfacl /data/file.txt
B.chacl /data/file.txt
C.lsacl /data/file.txt
D.aclshow /data/file.txt
AnswerA

The trailing plus sign in the permission string signals that an extended ACL is attached to the file. getfacl reads and displays those access control entries, including named users, groups and masks, which ls does not show. This directly satisfies the requirement to view current ACL entries.

Why this answer

The `+` at the end of the permission string (`-rw-r-----+`) indicates that the file has extended ACL (Access Control List) entries beyond the standard Unix permissions. The `getfacl` command is the standard Linux utility to display the current ACL entries for a file or directory, showing user, group, and mask entries along with any named user or group ACLs.

Exam trap

A common pitfall on the CompTIA Linux+ exam is confusing `chacl` (used for changing ACLs) with `getfacl`, or assuming a command like `lsacl` exists because of the pattern `ls` for listing, when in fact `getfacl` is the correct utility to view ACL entries.

How to eliminate wrong answers

Option B (`chacl`) is wrong because `chacl` is used to change or set ACLs, not to view them; it requires an ACL specification as an argument and modifies the ACL rather than displaying it. Option C (`lsacl`) is wrong because there is no standard Linux command named `lsacl`; the correct command to list ACLs is `getfacl`, and `lsacl` is not a valid utility. Option D (`aclshow`) is wrong because `aclshow` is not a standard Linux command; it may be confused with `getfacl` or a command from a non-standard package, but it does not exist in typical Linux distributions.

672
MCQmedium

SELinux is currently in enforcing mode. A service is being blocked by SELinux. Which command can analyze the audit log and suggest the minimum policy changes to allow the service?

A.ausearch
B.audit2allow
C.setsebool
D.restorecon
AnswerB

audit2allow reads SELinux denial records from the audit log and generates allow rules targeting the exact permissions the service was refused. This produces the minimum policy change needed, rather than disabling enforcement or granting broad access, directly satisfying the requirement to suggest least-privilege policy adjustments.

Why this answer

audit2allow reads SELinux denial messages from the audit log (or standard input) and generates a human-readable policy module that allows the previously denied operations. It is specifically designed to translate raw AVC denials into the minimal set of allow rules needed, which can then be compiled and loaded with semodule. This directly matches the requirement to analyze the audit log and suggest minimum policy changes.

Exam trap

The trap here is confusing tools that display audit logs (ausearch) with tools that generate policy from them (audit2allow), or assuming that setsebool or restorecon can dynamically create new allow rules when they only toggle existing booleans or fix file contexts.

How to eliminate wrong answers

Option A is wrong because ausearch only queries and filters audit logs; it displays denial events but does not generate policy suggestions or allow rules. Option C is wrong because setsebool toggles existing SELinux booleans on or off, but it does not analyze audit logs or create new policy rules. Option D is wrong because restorecon resets the SELinux context of files to their default values based on policy, which addresses file labeling issues but does not analyze audit logs or suggest policy changes.

673
Multi-Selecthard

A Linux administrator is troubleshooting a systemd service that fails to start. The service unit file is located at /etc/systemd/system/myapp.service. Which two commands should the administrator use to reload the systemd manager configuration and then restart the service? (Choose two.)

Select 2 answers
A.systemctl reload myapp.service
B.systemctl daemon-reload
C.systemctl enable myapp.service
D.systemctl reexec myapp.service
E.systemctl restart myapp.service
AnswersB, E

systemctl daemon-reload reloads the systemd manager configuration, including unit files. After modifying a unit file, this command is necessary for systemd to recognize changes. It does not restart services but ensures the new configuration is loaded before attempting to restart the service.

Why this answer

After editing a unit file, the administrator must run systemctl daemon-reload to make systemd aware of the changes. Then, systemctl restart myapp.service stops and starts the service with the new configuration. The other commands either do not reload the manager configuration, are invalid, or serve a different purpose such as enabling at boot.

Exam trap

The trap here is confusing systemctl daemon-reload with systemctl reload, and assuming that enabling a service or reexecuting the manager will apply unit file changes.

674
MCQmedium

A system administrator is configuring centralized logging for a cluster of web servers. Each web server runs rsyslog and needs to forward its Apache access logs to a central log server at 192.168.1.100 over UDP port 514. The administrator adds the following line to /etc/rsyslog.conf on each web server: '*.* @192.168.1.100:514'. After restarting rsyslog, no logs appear on the central server. The administrator checks the network connectivity and finds that the central server is reachable and listening on UDP 514. Which additional configuration is most likely required on the web servers to forward the Apache logs?

A.Enable the 'imuxsock' module in rsyslog to listen on a Unix socket for Apache logs.
B.Create a configuration file in /etc/rsyslog.d/ with a more specific filter for Apache logs.
C.Configure Apache to send access logs to syslog using the 'syslog' facility in the LogFormat directive.
D.Change the forwarding protocol from UDP to TCP in both the sender and receiver.
AnswerC

The '*.* @192.168.1.100:514' rule forwards whatever syslog receives, but Apache writes access logs to files by default, not to syslog. Configuring the LogFormat directive with the syslog facility makes Apache emit entries into syslog, which rsyslog then forwards.

Why this answer

Apache writes access logs to files by default, not to syslog, so rsyslog's '*.*' rule never sees the Apache log lines. The administrator must reconfigure Apache's LogFormat to use the syslog facility (or pipe logs to logger), which causes Apache to emit access log entries into the local syslog socket that rsyslog then forwards to the central server.

Exam trap

XK0-006 often tests the assumption that rsyslog can forward any log file on disk — the trap is forgetting that rsyslog only forwards messages delivered to it via syslog, journal, or network, not arbitrary files Apache writes.

How to eliminate wrong answers

Option A is wrong because imuxsock is already loaded by default in most rsyslog configurations and it listens on the local Unix socket for messages from applications that already use syslog — it does not make Apache start using syslog. Option B is wrong because creating a more specific filter in /etc/rsyslog.d/ only changes which messages rsyslog forwards; if Apache never sends messages to rsyslog, no filter will help. Option D is wrong because switching from UDP to TCP changes transport reliability, not whether Apache logs reach rsyslog at all — the logs still are not being generated into syslog.

675
MCQhard

A Linux administrator is troubleshooting a service that fails to start at boot. The service unit file is present in `/etc/systemd/system/` and has been enabled. Running `systemctl status myservice` shows it as `inactive (dead)`. Which command should the administrator run to see the most recent boot messages for this service?

A.systemctl cat myservice
B.grep myservice /var/log/boot.log
C.journalctl -u myservice -b
D.systemctl show myservice
AnswerC

`journalctl -u myservice -b` filters the journal for messages from the specified unit and limits output to the current boot. This shows all log entries for the service since the last boot, which is exactly what the administrator needs to diagnose why the service failed to start at boot.

Why this answer

To see boot-time messages for a specific systemd service, the correct tool is `journalctl` with the `-u` (unit) and `-b` (current boot) options. This filters the journal to show only entries from that unit during the current boot. Other commands either show unit file contents, unit properties, or rely on a non-authoritative log file, and none provide the targeted boot logs needed.

Exam trap

The trap here is assuming that `systemctl status` or `systemctl show` includes historical boot logs, when they only show current state and properties.

Page 8

Page 9 of 11

Page 10

All pages