XK0-006 Troubleshooting Practice Question
An administrator is troubleshooting a service that fails to start with a 'Permission denied' error. The administrator runs `strace -f -o /tmp/strace.log systemctl start myservice`. Which of the following best describes what this command achieves?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It traces system calls for systemctl and its children, recording them to a file.
strace traces system calls; -f follows child processes; -o writes output to file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It records the kernel messages related to the service start.
Why it's wrong here
strace intercepts system calls and signals, writing them to the log; it does not read the kernel ring buffer. dmesg, or journalctl -k, records kernel messages such as driver and link events, which is what this option describes.
- ✓
It traces system calls for systemctl and its children, recording them to a file.
Why this is correct
strace attaches to systemctl and, with -f, follows forked child processes, while -o writes the captured system calls to /tmp/strace.log. This reveals the exact syscall returning EACCES, pinpointing the permission failure without flooding the terminal.
- ✗
It monitors network connections opened by the service.
Why it's wrong here
strace records system calls and signals, not socket traffic; network connections are shown by ss, netstat or tcpdump. Those tools would be chosen when the fault is a connectivity or port-binding issue rather than a permission denial during startup.
- ✗
It traces library calls made by the service startup.
Why it's wrong here
strace traces system calls into the kernel, not user-space library calls. Library call tracing is the job of ltrace, which would be the right tool when a program fails inside a shared library rather than at a syscall boundary.
Go deeper
Related to this question
Learn chapter
File Transfer and Remote Access
Key term
systemctl
systemctl is the command-line tool used to inspect, start, stop, enable, or disable services managed by the systemd init system in Linux.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.