Courseiva
Troubleshooting →hardMultiple Choice

XK0-006 Troubleshooting Practice Question

An administrator is troubleshooting a service that fails to start. They want to trace the system calls made by the service binary. Which command should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

strace

strace traces system calls and signals. It is used to debug what a program is doing at the kernel level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ltrace

    Why it's wrong here

    ltrace intercepts library calls, not kernel system calls, so it cannot show the service's open, execve or socket syscalls. It is tempting because it traces dynamic library invocations, which is the right tool when diagnosing failures inside shared libraries rather than kernel interactions.

  • ✗

    dmesg

    Why it's wrong here

    dmesg prints the kernel ring buffer, which records driver and hardware messages but not the syscalls a binary issues at runtime. It is tempting because boot-time kernel errors often explain why a service fails, making it the right choice when diagnosing hardware or module faults.

  • ✓

    strace

    Why this is correct

    strace attaches to the process and prints each system call with arguments and return values, exposing where startup fails, such as a missing file or denied permission. It satisfies the requirement to trace system calls made by the service binary.

  • ✗

    lsof

    Why it's wrong here

    lsof lists open file descriptors and network sockets held by running processes; it never records the syscall sequence a binary executes. It is tempting because a service failing to start often stems from a locked port or missing file, which lsof reveals.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.