Courseiva
Troubleshooting →hardMultiple Choice

XK0-006 Troubleshooting Practice Question

An administrator is troubleshooting a service that fails to start with a 'Permission denied' error. The administrator runs `strace -f -o /tmp/strace.log systemctl start myservice`. Which of the following best describes what this command achieves?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It traces system calls for systemctl and its children, recording them to a file.

strace traces system calls; -f follows child processes; -o writes output to file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It records the kernel messages related to the service start.

    Why it's wrong here

    strace intercepts system calls and signals, writing them to the log; it does not read the kernel ring buffer. dmesg, or journalctl -k, records kernel messages such as driver and link events, which is what this option describes.

  • ✓

    It traces system calls for systemctl and its children, recording them to a file.

    Why this is correct

    strace attaches to systemctl and, with -f, follows forked child processes, while -o writes the captured system calls to /tmp/strace.log. This reveals the exact syscall returning EACCES, pinpointing the permission failure without flooding the terminal.

  • ✗

    It monitors network connections opened by the service.

    Why it's wrong here

    strace records system calls and signals, not socket traffic; network connections are shown by ss, netstat or tcpdump. Those tools would be chosen when the fault is a connectivity or port-binding issue rather than a permission denial during startup.

  • ✗

    It traces library calls made by the service startup.

    Why it's wrong here

    strace traces system calls into the kernel, not user-space library calls. Library call tracing is the job of ltrace, which would be the right tool when a program fails inside a shared library rather than at a syscall boundary.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.