XK0-006 Troubleshooting Practice Question
An administrator needs to trace system calls made by a process that is misbehaving. Which command should be used to attach to the running process and display its system calls?
⚠ Common exam trap
The trap is confusing strace (system calls) with ltrace (library calls) — candidates who don't distinguish kernel syscalls from userspace library calls pick ltrace, or they pick lsof thinking it traces activity when it only lists open resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
strace -p <PID>
strace is the standard Linux utility for tracing system calls made by a process. Using strace -p <PID> attaches to an already-running process and displays its system calls in real time, which is exactly what is needed to diagnose a misbehaving process at the kernel interface level. This makes it the correct tool for observing file opens, reads, writes, network calls, and signal handling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tcpdump -i any
Why it's wrong here
tcpdump captures network packets traversing interfaces; it cannot show the syscall interface between a process and the kernel. It is tempting because tcpdump also attaches to live traffic and diagnoses misbehaving services, and it would be correct for inspecting packet contents, retransmissions or connection resets.
- ✗
ltrace -p <PID>
Why it's wrong here
ltrace attaches with -p, but it intercepts library calls such as malloc or printf, not the kernel syscall boundary. It is tempting because it traces a running process by PID, and it would be correct for diagnosing failures inside dynamically linked library functions rather than direct system calls.
- ✓
strace -p <PID>
Why this is correct
`strace -p <PID>` attaches to an already-running process via ptrace and prints each system call it makes, satisfying the requirement to trace a misbehaving process without restarting it. The `-p` flag targets the live PID directly, which is exactly what the scenario demands.
- ✗
lsof -p <PID>
Why it's wrong here
lsof -p lists open file descriptors, sockets and mapped files for a process; it reports resources already held rather than the syscalls being issued. It is tempting because it attaches to a live PID, and it would be correct for identifying which files or ports a process currently has open.
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.