XK0-006 System Management Practice Question
An administrator needs to monitor a service's log output and wants systemd to capture the output of a specific service unit into the journal, tagged so it can be filtered by the unit name. The administrator also wants to limit how much disk space the journal may consume so it does not fill the root filesystem. Which configuration accomplishes both goals?
⚠ Common exam trap
Watch out — candidates often confuse runtime-only journal limits such as RuntimeMaxUse with persistent limits like SystemMaxUse, and assuming file redirection still populates the journal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set SystemMaxUse in /etc/systemd/journald.conf and ensure the service logs to the journal via StandardOutput=journal in its unit file
Capturing a service's output in the journal with unit tagging requires the unit to send output to the journal, and journald limits total disk usage through SystemMaxUse in journald.conf. Filtering by unit then works with journalctl -u. Disabling storage, redirecting output to files, or limiting only the runtime journal fails to both capture and cap the data as required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set RuntimeMaxUse in journald.conf and add StandardOutput=file:/var/log/report.log to the service unit
Why it's wrong here
RuntimeMaxUse limits only the volatile /run journal, not the persistent journal on disk, so it does not protect the root filesystem. Redirecting standard output to a file bypasses the journal entirely, so entries are not tagged by unit and cannot be filtered with journalctl -u. Neither goal is satisfied by this configuration.
- ✗
Set Storage=none in journald.conf and add StandardOutput=syslog to the service unit
Why it's wrong here
Storage=none disables persistent journal storage entirely, so no entries are written to disk and size limiting becomes moot, which contradicts the goal of capturing and retaining output. StandardOutput=syslog routes output to the syslog socket instead of the journal, so journalctl -u filtering would not work as intended for this service.
- ✗
Set MaxLevelStore in journald.conf and add StandardError=null to the service unit
Why it's wrong here
MaxLevelStore controls which message priorities are stored, not the total disk footprint, so it does not limit journal size. StandardError=null discards standard error output, meaning important error messages from the service would be lost rather than captured and tagged. This combination fails to meet either stated objective.
- ✓
Set SystemMaxUse in /etc/systemd/journald.conf and ensure the service logs to the journal via StandardOutput=journal in its unit file
Why this is correct
journald collects service output when a unit uses StandardOutput=journal, and entries are tagged with the unit's identifier so journalctl -u can filter them. Setting SystemMaxUse in journald.conf caps the persistent journal's disk consumption, preventing it from filling the root filesystem. Together these satisfy both the tagging and size-limit requirements.
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
Output
In IT service management, output is the result or deliverable produced by a process, system, or component, such as data, reports, or services delivered to a customer.
Key term
journald
journald is the systemd logging service that collects, stores, and manages system logs on modern Linux distributions, providing structured log data and binary log files.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.