Courseiva
Troubleshooting →hardMultiple Choice

XK0-006 Troubleshooting Practice Question

An administrator needs to trace system calls made by a process that is misbehaving. Which command should be used to attach to the running process and display its system calls?

⚠ Common exam trap

The trap is confusing strace (system calls) with ltrace (library calls) — candidates who don't distinguish kernel syscalls from userspace library calls pick ltrace, or they pick lsof thinking it traces activity when it only lists open resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

strace -p <PID>

strace is the standard Linux utility for tracing system calls made by a process. Using strace -p <PID> attaches to an already-running process and displays its system calls in real time, which is exactly what is needed to diagnose a misbehaving process at the kernel interface level. This makes it the correct tool for observing file opens, reads, writes, network calls, and signal handling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tcpdump -i any

    Why it's wrong here

    tcpdump captures network packets traversing interfaces; it cannot show the syscall interface between a process and the kernel. It is tempting because tcpdump also attaches to live traffic and diagnoses misbehaving services, and it would be correct for inspecting packet contents, retransmissions or connection resets.

  • ✗

    ltrace -p <PID>

    Why it's wrong here

    ltrace attaches with -p, but it intercepts library calls such as malloc or printf, not the kernel syscall boundary. It is tempting because it traces a running process by PID, and it would be correct for diagnosing failures inside dynamically linked library functions rather than direct system calls.

  • ✓

    strace -p <PID>

    Why this is correct

    `strace -p <PID>` attaches to an already-running process via ptrace and prints each system call it makes, satisfying the requirement to trace a misbehaving process without restarting it. The `-p` flag targets the live PID directly, which is exactly what the scenario demands.

  • ✗

    lsof -p <PID>

    Why it's wrong here

    lsof -p lists open file descriptors, sockets and mapped files for a process; it reports resources already held rather than the syscalls being issued. It is tempting because it attaches to a live PID, and it would be correct for identifying which files or ports a process currently has open.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.