Courseiva

CCNA System Management Questions

75 of 131 questions · Page 1/2 · System Management · Answers revealed

1
MCQmedium

A Linux administrator needs to change the runlevel of a systemd-based system to a state where only a single user can log in for maintenance, without starting network services. Which systemd target should the administrator use?

A.emergency.target
B.multi-user.target
C.graphical.target
D.rescue.target
AnswerD

The rescue.target is a systemd target that provides a single-user environment with basic system services, but does not start network services. It is equivalent to the traditional runlevel 1 (single-user mode). This target is designed for maintenance and allows only the root user to log in on the console.

Why this answer

The rescue.target is the systemd equivalent of single-user mode, providing a minimal environment with only essential services and no networking. It allows the administrator to log in as root for maintenance tasks. The emergency.target is more restrictive and mounts the root filesystem read-only, while multi-user and graphical targets start networking and multiple users.

Therefore, rescue.target is the correct choice.

Exam trap

The trap here is confusing rescue.target with emergency.target; rescue.target provides a usable single-user shell with basic services, while emergency.target is even more minimal and may not allow normal login.

2
MCQmedium

An administrator wants to replace all occurrences of 'oldstring' with 'newstring' in a configuration file named config.cfg, and save the changes. Which sed command should be used?

A.sed -i 's/oldstring/newstring/' config.cfg
B.sed -i 's/oldstring/newstring/g' config.cfg
C.sed -i 's/oldstring/newstring/gi' config.cfg
D.sed 's/oldstring/newstring/' config.cfg
AnswerB

The -i flag edits config.cfg in place, satisfying the requirement to save changes, and the g flag replaces every occurrence of oldstring on each line with newstring. Omitting g would substitute only the first match per line, leaving later instances unchanged.

Why this answer

It uses -i for in-place editing and g to replace all occurrences on each line. Option A has -i but lacks g, so it replaces only the first occurrence per line. Option C adds an unnecessary i flag for case-insensitive matching, which deviates from the requirement to replace 'oldstring' exactly as given.

Option D lacks -i, so changes are only printed to stdout and not saved.

3
MCQmedium

A system administrator wants to change the priority of a running process with PID 1234 to a lower priority (higher nice value). Which command should be used?

A.renice -n 10 -p 1234
B.renice -n -10 -p 1234
C.chrt -p 10 1234
D.nice -n 10 -p 1234
AnswerA

`renice -n 10 -p 1234` adjusts the nice value of an already-running process, satisfying the stem's requirement to alter priority without restarting it. The `-p` flag targets PID 1234 directly, and a positive nice value of 10 lowers scheduling priority, unlike `nice`, which only sets priority when launching a new process.

Why this answer

renice is used to change the nice value of an existing process. A higher nice value means lower priority.

4
MCQmedium

A Linux administrator is preparing a new server that uses systemd-boot as the boot loader. The administrator wants to verify the current boot loader entries and their order. Which command should the administrator run?

A.efibootmgr -v
B.grub-mkconfig -o /boot/grub/grub.cfg
C.systemctl status systemd-boot
D.bootctl list
AnswerD

The bootctl command is the systemd-boot manager. With the list subcommand, it enumerates all boot loader entries found in the EFI system partition and shows their order, including the default entry. This directly fulfills the requirement to verify the current entries and their order on a system using systemd-boot.

Why this answer

The bootctl list command displays all systemd-boot entries and their sequence, which is exactly what the administrator needs to verify the boot loader configuration on a system using systemd-boot. The other tools either manage different boot loaders (GRUB), interact with UEFI firmware (efibootmgr), or assume systemd-boot is a service (systemctl), so they do not provide the required information.

Exam trap

The trap here is assuming that efibootmgr shows systemd-boot entry order, but efibootmgr only shows UEFI firmware boot entries, not systemd-boot configuration files.

5
MCQeasy

Which command is used to display the contents of the systemd journal for a specific unit?

A.systemctl status unit
B.dmesg
C.journalctl -f
D.journalctl -u
AnswerD

Using `journalctl -u` filters the systemd journal by unit name, satisfying the requirement to display entries for one specific unit. The `-u` flag accepts a unit such as `sshd.service`, restricting output to that unit's messages rather than the entire journal.

Why this answer

journalctl -u unitname displays logs for the specified systemd unit.

6
MCQhard

An administrator needs to schedule a backup script to run every Monday at 2:00 AM. Which crontab entry will accomplish this?

A.2 0 * * 1 /path/to/backup.sh
B.0 2 * * 0 /path/to/backup.sh
C.0 2 1 * * /path/to/backup.sh
D.0 2 * * 1 /path/to/backup.sh
AnswerD

This crontab entry specifies minute 0, hour 2, any day of month, any month, and day of week 1 (Monday). It correctly runs the backup script at 2:00 AM every Monday. The fields are in the order: minute, hour, day of month, month, day of week, command.

Why this answer

The correct crontab entry must set minute to 0, hour to 2, and day of week to 1 (Monday). The fields are minute, hour, day of month, month, day of week, command. The entry '0 2 * * 1 /path/to/backup.sh' satisfies these conditions and schedules the backup for every Monday at 2:00 AM.

Exam trap

The trap here is mixing up the order of hour and minute fields, or confusing day of week numbering where 0 is Sunday and 1 is Monday.

7
MCQmedium

A Linux administrator needs to locate all files in the /var/log directory that have been modified within the last 2 days and contain the word 'error' (case-insensitive). Which command accomplishes this?

A.find /var/log -mtime +2 -exec grep -li 'error' {} \;
B.find /var/log -name '*error*' -mtime -2
C.find /var/log -mtime -2 -exec grep -l 'error' {} \;
D.find /var/log -mtime -2 -exec grep -li 'error' {} \;
AnswerD

The `-mtime -2` predicate filters files modified within the last two days, satisfying the recency constraint, while `-exec grep -li 'error' {} \;` runs a case-insensitive search on each match. The `-l` flag lists only filenames rather than matching lines, and `-i` handles the case-insensitivity requirement.

Why this answer

The correct command uses -mtime -2 to find files modified less than 2 days ago, and -exec grep -li 'error' to perform a case-insensitive search for 'error' in file contents, listing filenames. Option A uses -mtime +2 (files older than 2 days). Option B uses -name to match filenames, not content.

Option C uses grep -l without -i, so it would miss case variations.

8
MCQhard

A technician wants to create a symbolic link in /usr/local/bin that points to /opt/myapp/bin/start.sh. The technician has write permissions to /usr/local/bin. Which command should be used?

A.ln -s /opt/myapp/bin/start.sh /usr/local/bin/start.sh
B.ln -s /usr/local/bin/start.sh /opt/myapp/bin/start.sh
C.ln /opt/myapp/bin/start.sh /usr/local/bin/start.sh
D.cp -s /opt/myapp/bin/start.sh /usr/local/bin/start.sh
AnswerA

`ln -s` creates a symbolic link, with the target path first and the link path second, satisfying the requirement to point /usr/local/bin/start.sh at /opt/myapp/bin/start.sh. Write permission on /usr/local/bin is sufficient; no elevated privileges are needed since the technician already holds them.

Why this answer

ln -s target linkname creates a symbolic link. The target should be the file to link to, and the link name is the new symlink.

9
Multi-Selectmedium

A Linux administrator needs to view real-time information about running processes, including CPU and memory usage. Which TWO commands can be used for this purpose? (Choose two.)

Select 2 answers
A.ps aux
B.top
C.systemctl list-units
D.htop
E.kill -l
AnswersB, D

top reads /proc to render a live, refreshing table of processes with per-process CPU and memory figures, satisfying the real-time monitoring requirement. Its interactive sort and kill functions let the administrator act on what they observe without leaving the terminal.

Why this answer

Option B (top) is correct because top provides a continuously refreshing, real-time view of running processes along with per-process CPU and memory usage, load averages, and system summary statistics. Option D (htop) is correct because htop is an interactive process viewer that also displays real-time CPU and memory usage per process, with additional features like colorized output, scrolling, and process management. Option A (ps aux) is not correct here because ps produces a static snapshot of processes at the moment it is executed rather than a live, updating view.

Option C (systemctl list-units) is incorrect because it lists systemd units and their states, not per-process CPU or memory usage. Option E (kill -l) is incorrect because it only lists available signal names/numbers and provides no process resource information.

10
MCQmedium

A technician needs to kill a process with PID 1234 that is not responding to normal termination. Which command sends SIGKILL?

A.kill 1234
B.kill -15 1234
C.kill -9 1234
D.kill -1 1234
AnswerC

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 1234 immediately. This satisfies the stem's constraint that the process is unresponsive to normal termination, unlike SIGTERM (15), which the process may handle or defer.

Why this answer

kill -9 sends SIGKILL, which forcefully terminates the process.

11
MCQeasy

Which of the following directories in the Filesystem Hierarchy Standard (FHS) contains variable data files such as logs, spool files, and temporary files that persist across reboots?

A./opt
B./etc
C./tmp
D./var
AnswerD

/var holds variable data — logs, spool queues and persistent temporary files — which change in size and content during normal operation. The FHS reserves it precisely for data that must survive reboots, unlike /tmp, which is typically cleared. This satisfies the stem's requirement for variable files persisting across restarts.

Why this answer

/var is for variable data like logs, spool, and temporary files that persist. /tmp is for temporary files that may be cleared on reboot. /etc is for configuration files. /opt is for optional add-on software.

12
Multi-Selectmedium

A technician wants to extract the third column of a tab-separated file and sort the output uniquely. Which three commands can be combined using pipes to achieve this? (Choose three.)

Select 3 answers
A.cut -f3
B.tee
C.wc -l
D.sort
E.uniq
AnswersA, D, E

`cut -f3` extracts the third tab-delimited field, satisfying the column-selection requirement. Its default delimiter is TAB, matching the tab-separated file, so no `-d` flag is needed. Piped into `sort` and `uniq`, it produces the uniquely sorted output the technician wants.

Why this answer

Option A, `cut -f3`, is correct because `cut` with the `-f3` flag extracts the third field from each line, and with tab as the default delimiter it directly targets the third column of a tab-separated file. Option D, `sort`, is correct because it orders the extracted lines so that duplicate values become adjacent, which is a prerequisite for `uniq` to collapse them. Option E, `uniq`, is correct because it removes adjacent duplicate lines, producing the unique output the technician wants when chained after `sort`.

Option B, `tee`, is not appropriate because it merely splits output to a file and standard output rather than extracting or deduplicating data. Option C, `wc -l`, is not appropriate because it only counts lines and does not extract or sort columns.

13
MCQmedium

A service called 'myapp' fails to start automatically after a system reboot. The administrator wants to ensure the service starts at boot. Which systemctl command should be used?

A.systemctl daemon-reload
B.systemctl start myapp
C.systemctl enable myapp
D.systemctl reenable myapp
AnswerC

`systemctl enable myapp` creates the symlinks that pull the unit into the boot target's dependency tree, so systemd starts it automatically at each reboot. This directly satisfies the requirement that the service start at boot, unlike `start`, which only launches it for the current session.

Why this answer

The `systemctl enable myapp` command creates the necessary symlinks in the systemd unit configuration directories (typically `/etc/systemd/system/multi-user.target.wants/`) so that the `myapp` service is automatically started at boot. This is the correct approach because the question specifically asks to ensure the service starts after a reboot, not to start it immediately.

Exam trap

The trap here is that candidates often confuse `systemctl start` (immediate start) with `systemctl enable` (boot-time start), or they mistakenly think `systemctl reenable` is a valid command for re-enabling a service.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` reloads the systemd manager configuration and unit files, but it does not enable a service to start at boot. Option B is wrong because `systemctl start myapp` starts the service immediately in the current session but does not configure it to start automatically after a reboot. Option D is wrong because `systemctl reenable myapp` is not a valid systemctl command; the correct command to re-enable a service is `systemctl enable myapp` (which can be run again to recreate symlinks), and `reenable` is a common misconception or typo.

14
MCQeasy

A Linux administrator needs to locate all files in /var/log that were modified more than 7 days ago. Which command should be used?

A.find /var/log -mtime +7
B.grep -mtime +7 /var/log
C.ls -mtime +7 /var/log
D.locate -mtime +7 /var/log
AnswerA

The +7 argument to -mtime matches files whose modification time is greater than seven 24-hour periods ago, exactly the age threshold the stem specifies. The minus form would instead select files modified within the last seven days.

Why this answer

The find command with -mtime +7 finds files modified more than 7 days ago. locate uses a database and does not support -mtime; grep is for text search; ls does not filter by modification time.

15
MCQhard

A system administrator needs to install a package from a local RPM file without resolving dependencies automatically. Which command should be used?

A.rpm -i package.rpm
B.rpm -U package.rpm
C.yum localinstall package.rpm
D.dnf install ./package.rpm
AnswerA

The rpm -i command installs a local package file directly without contacting repositories or resolving dependencies, matching the requirement to skip automatic dependency resolution. Tools like dnf or yum would instead fetch and resolve dependencies.

Why this answer

The `rpm -i package.rpm` command installs the specified RPM package without automatically resolving dependencies. The `-i` flag stands for 'install' and, unlike `-U` (upgrade) or higher-level tools like `yum` or `dnf`, it does not attempt to fetch or satisfy missing dependencies from configured repositories. This is the correct choice when the requirement is to install a local RPM file while explicitly avoiding automatic dependency resolution.

Exam trap

The trap here is that candidates often confuse `rpm -i` with `rpm -U` or assume that higher-level tools like `yum` or `dnf` can be used to install local RPMs without dependency resolution, but those tools are designed to automatically resolve dependencies, which directly violates the question's constraint.

How to eliminate wrong answers

Option B is wrong because `rpm -U package.rpm` performs an upgrade or install, but it still does not resolve dependencies automatically; however, the question specifically asks for a command that installs without resolving dependencies, and `-U` is semantically an upgrade operation, not a pure install. Option C is wrong because `yum localinstall package.rpm` is a higher-level command that resolves and installs dependencies from repositories, which contradicts the requirement to avoid automatic dependency resolution. Option D is wrong because `dnf install ./package.rpm` also resolves dependencies automatically using DNF's dependency solver, making it unsuitable for the stated requirement.

16
MCQmedium

A system administrator wants to view the last 10 lines of a log file and also save those lines to another file for analysis. Which command should the administrator use?

A.head -n 10 file | tee output.txt
B.cat file | tee output.txt
C.tail -n 10 file | tee output.txt
D.tee output.txt < tail -n 10 file
AnswerC

tail -n 10 extracts the final ten lines, and piping into tee writes them to output.txt while also displaying them on stdout. Redirection with > would suppress terminal output, and tee -a would append rather than create, so this pipeline satisfies both viewing and saving.

Why this answer

The command 'tail -n 10 file | tee output.txt' displays the last 10 lines of the file and simultaneously writes those lines to output.txt. The tail command extracts the last 10 lines, and tee duplicates the output to both the terminal and the specified file.

Exam trap

XK0-006 often tests the difference between head and tail, and the correct usage of tee with pipes; candidates may confuse head with tail or misuse redirection syntax.

How to eliminate wrong answers

Option A is wrong because 'head -n 10' displays the first 10 lines, not the last 10. Option B is wrong because 'cat file | tee output.txt' outputs the entire file, not just the last 10 lines. Option D is wrong because the syntax 'tee output.txt < tail -n 10 file' is invalid; input redirection cannot be used with a command as a file, and tee expects input from stdin, not from a command substitution in that form.

17
MCQhard

An administrator is troubleshooting a service that fails to start. The administrator wants to view the last 50 lines of the service's journal log entries from the current boot. Which journalctl command should be used?

A.journalctl -f -n 50 -u service
B.journalctl -u service --since today
C.journalctl -x -n 50 -u service
D.journalctl -u service -b -n 50
AnswerD

Filtering with `-u service` isolates that unit's entries, `-b` restricts output to the current boot, and `-n 50` returns only the last 50 lines — satisfying every constraint in the stem simultaneously. Omitting any flag would show other units, previous boots, or the entire journal.

Why this answer

The command journalctl -u service -b -n 50 filters by unit (-u), restricts to the current boot (-b), and shows the last 50 lines (-n 50), which exactly matches the requirement. The -b flag is the key differentiator because it limits output to the current boot session, avoiding entries from prior boots.

Exam trap

XK0-006 often tests flag combinations that look similar — candidates confuse -f (follow) with -n (number of lines) and forget that -b is required to scope to the current boot, picking options that filter by time instead.

How to eliminate wrong answers

Option A is wrong because -f follows the journal in real time (like tail -f) and does not restrict to the current boot; it also blocks the terminal, which is not what the administrator asked for. Option B is wrong because --since today filters by time, not by boot session, so it may include entries from earlier boots that occurred today and does not guarantee the last 50 lines. Option C is wrong because -x adds explanatory/catalog context to messages but does not restrict to the current boot, so it may return entries from previous boots.

18
MCQeasy

A Linux administrator needs to scan all currently connected USB devices and display detailed information such as vendor ID, product ID, and device class. Which command should the administrator run?

A.lsusb
B.lshw -class usb
C.lspci
D.lsblk
AnswerA

lsusb enumerates USB buses and connected devices, showing vendor and product IDs, device class, and bus/device numbers. It directly answers the need to list currently connected USB devices with detailed identification information without requiring root privileges.

Why this answer

The lsusb command queries the USB subsystem and prints a line for each connected USB device, including vendor and product IDs, device class, and bus topology. It is the standard utility for quickly enumerating USB devices on a Linux system without needing elevated privileges.

Exam trap

The trap here is confusing PCI device listing with USB device listing; lspci shows internal buses, not external USB peripherals.

19
MCQeasy

Which command displays the amount of disk space used and available on mounted filesystems in a human-readable format (e.g., GB, MB)?

A.df -h
B.lsblk
C.du -h
D.fdisk -l
AnswerA

The -h flag converts df's default 1K-block output into human-readable units such as GB and MB, while df itself reports used and available space per mounted filesystem. This satisfies the requirement for human-readable capacity figures.

Why this answer

The `df -h` command displays disk space usage for all mounted filesystems, with the `-h` flag converting raw block counts into human-readable units like GB or MB. This is the standard Linux utility for reporting filesystem capacity, usage, and available space, making it the correct choice for the question.

Exam trap

The trap here is that candidates confuse `du -h` (which shows directory-level usage) with `df -h` (which shows filesystem-level capacity), leading them to select option C when the question explicitly asks for disk space on mounted filesystems.

How to eliminate wrong answers

Option B is wrong because `lsblk` lists block devices (e.g., disks and partitions) and their attributes, but it does not show disk space usage or available capacity in human-readable format. Option C is wrong because `du -h` estimates file and directory space usage, not the total disk space used and available on mounted filesystems. Option D is wrong because `fdisk -l` displays partition table information for block devices, not current filesystem usage or available space.

20
MCQmedium

A system administrator needs to change the hostname of a Linux server running systemd to 'webserver01'. Which command will accomplish this?

A.hostnamectl set-hostname webserver01
B.hostname webserver01
C.sysctl kernel.hostname=webserver01
D.echo webserver01 > /etc/hosts
AnswerA

hostnamectl is the systemd utility for managing hostnames. The set-hostname subcommand sets the static hostname to the specified value. This change is persistent across reboots and updates /etc/hostname. It is the recommended method on modern Linux distributions using systemd.

Why this answer

On systemd-based systems, hostnamectl is the correct tool to set the hostname persistently. The set-hostname subcommand updates the static hostname and writes it to /etc/hostname, ensuring it survives reboots. Other methods like the hostname command or sysctl are temporary or incorrect for this purpose.

Exam trap

The trap here is using the hostname command, which only changes the hostname temporarily, rather than hostnamectl for a persistent change.

21
MCQhard

A developer wants to grant a user named 'john' read and write permissions to a file, but the file currently has an ACL that gives 'jane' full control. The administrator wants to add an ACL entry for 'john' without modifying existing entries. Which command accomplishes this?

A.setfacl -x u:john:rw file
B.setfacl -b u:john:rw file
C.chmod u+rw file; setfacl -m u:john:rw file
D.setfacl -m u:john:rw file
AnswerD

The -m flag modifies the ACL by adding or replacing only the specified entry, leaving jane's existing full-control entry untouched. Using u:john:rw grants john read and write, satisfying the stem's requirement to avoid altering existing entries.

Why this answer

The `setfacl -m` command modifies the ACL by adding or updating an entry for the specified user, leaving all other existing ACL entries intact. This directly satisfies the requirement to grant 'john' read and write permissions without altering 'jane's full control entry. The `-m` flag is specifically designed for modifying ACLs in this additive manner.

Exam trap

XK0-006 often tests the distinction between modifying and removing ACL entries, so candidates may confuse `-m` (modify/add) with `-x` (remove) or `-b` (remove all).

How to eliminate wrong answers

Option A is wrong because `setfacl -x` removes the specified ACL entry, which would delete permissions rather than add them. Option B is wrong because `setfacl -b` removes all ACL entries except the base permissions, which would eliminate 'jane's entry and not add one for 'john'. Option C is wrong because `chmod u+rw file` modifies the file's base permissions for the owner, not an ACL entry for 'john', and then `setfacl -m` would add the entry but the chmod step is unnecessary and could inadvertently change owner permissions.

22
MCQmedium

A technician notices a script fails to execute because the user does not have permission. The script currently has permissions 644. The technician needs to add execute permission for the owner only. Which command accomplishes this?

A.chmod a+x script.sh
B.chmod 755 script.sh
C.chmod u+x script.sh
D.chmod 744 script.sh
AnswerC

`chmod u+x script.sh` adds execute permission solely for the file's owner, satisfying the stem's requirement to grant execute to the owner only. The `u` symbol targets user/owner, `+x` adds execute, and it leaves group and other permissions at their existing 644 values unchanged.

Why this answer

The script currently has permissions 644, meaning the owner has read/write (6), group has read (4), and others have read (4). The requirement is to add execute permission for the owner only. The command `chmod u+x script.sh` adds (+) execute (x) permission to the user (u) — the owner — without affecting group or others.

This is the precise and minimal command to achieve the goal.

Exam trap

The trap here is that candidates often confuse 'add execute for owner only' with setting permissions to 755 or using `a+x`, not realizing that `u+x` is the precise symbolic method to add execute solely for the user class without affecting group or others.

How to eliminate wrong answers

Option A is wrong because `chmod a+x script.sh` adds execute permission for all (a) — user, group, and others — which grants more permissions than required. Option B is wrong because `chmod 755 script.sh` sets permissions to rwxr-xr-x, which gives execute to owner, group, and others, not just the owner. Option D is wrong because `chmod 744 script.sh` sets permissions to rwxr--r--, which gives execute to the owner but also changes the owner's read/write permissions to read/write/execute (which is acceptable) and leaves group and others unchanged; however, it is not the minimal command (it explicitly sets all bits rather than just adding execute) and could inadvertently change other permissions if the original permissions were different, making it less precise than `chmod u+x`.

23
MCQhard

A process with PID 2345 is not responding. The administrator wants to force stop the process immediately. Which command should be used?

A.kill -9 2345
B.kill -1 2345
C.pkill -15 -f processname
D.kill -15 2345
AnswerA

SIGKILL (signal 9) cannot be caught, blocked or ignored by the process, so the kernel terminates PID 2345 immediately. This satisfies the requirement to force stop an unresponsive process, unlike the default SIGTERM sent by plain kill.

Why this answer

SIGKILL (signal 9) forcefully terminates a process. kill -9 2345 sends SIGKILL to PID 2345.

24
MCQmedium

A technician needs to search a log file for lines containing either 'ERROR' or 'FATAL' and display the line numbers. Which command accomplishes this?

A.grep -v -E 'ERROR|FATAL' logfile
B.grep -r -n 'ERROR|FATAL' logfile
C.grep -n -E 'ERROR|FATAL' logfile
D.grep -i 'ERROR|FATAL' logfile
AnswerC

grep -n prints line numbers, and -E enables extended regular expressions so the alternation ERROR|FATAL matches either pattern. This satisfies the requirement to find lines containing either term while displaying their line numbers in the log file.

Why this answer

grep -n -E 'ERROR|FATAL' logfile uses extended regex with alternation and -n for line numbers. -i ignores case, but the stem does not mention case-insensitive; -v inverts match; -r is recursive.

25
Multi-Selectmedium

An administrator wants to monitor real-time system resource usage to identify performance bottlenecks. Which two commands are suitable? (Choose two.)

Select 2 answers
A.top
B.vmstat
C.iostat
D.htop
E.sar
AnswersA, D

top renders a continuously refreshing view of CPU, memory and per-process usage, letting an administrator spot resource-hungry processes in real time. This satisfies the requirement to monitor live system resource usage for identifying performance bottlenecks.

Why this answer

Option A (top) is correct because it provides a real-time, continuously refreshing view of CPU, memory, load average, and per-process resource consumption, making it ideal for spotting live performance bottlenecks. Option D (htop) is also correct since it is an interactive process viewer that displays the same real-time system metrics as top but with a more user-friendly interface, color-coded resource bars, and scrolling, which helps identify bottlenecks as they occur. Option B (vmstat) is not the best fit here because it typically reports virtual memory, CPU, and I/O statistics at sampled intervals rather than offering an interactive real-time monitoring view.

Option C (iostat) is excluded because it focuses on I/O device and CPU statistics, usually in periodic reports, not a live interactive resource monitor. Option E (sar) is also not appropriate because it is designed to collect and report historical system activity data, often for later analysis rather than real-time bottleneck identification.

26
MCQeasy

A user wants to create a hard link named 'linkfile' to an existing file 'original'. Which command accomplishes this?

A.mv original linkfile
B.ln -s original linkfile
C.ln original linkfile
D.cp original linkfile
AnswerC

ln with two arguments creates a hard link by default, so 'ln original linkfile' makes linkfile an additional directory entry pointing to original's inode. This satisfies the requirement without the -s flag, which would create a symbolic link instead.

Why this answer

The ln command without -s creates a hard link. ln -s creates a symbolic link. cp copies the file; mv moves it.

27
MCQmedium

An administrator needs to replace all occurrences of 'oldhost' with 'newhost' in the file /etc/hosts. Which sed command should be used?

A.sed -e 's/oldhost/newhost/' /etc/hosts
B.sed -n 's/oldhost/newhost/gp' /etc/hosts
C.sed 's/oldhost/newhost/' /etc/hosts
D.sed -i 's/oldhost/newhost/g' /etc/hosts
AnswerD

The `-i` flag edits /etc/hosts in place, satisfying the requirement to replace content within that file directly. The `g` suffix applies the substitution to every occurrence per line, not merely the first, matching "all occurrences". Without `g`, only the initial match on each line would change.

Why this answer

sed -i 's/oldhost/newhost/g' /etc/hosts performs an in-place substitution globally.

28
MCQeasy

A technician wants to find all files owned by user 'jane' in the /home directory. Which command accomplishes this?

A.grep -r jane /home
B.ls -lR /home | grep jane
C.locate jane /home
D.find /home -type f -user jane
AnswerD

The -user predicate filters by owner, -type f restricts matches to regular files, and /home scopes the search to the required directory. This combination returns exactly the files owned by jane, satisfying the stem's ownership constraint without listing directories.

Why this answer

The find command with -user option searches for files owned by a specific user.

29
MCQeasy

Which command would a Linux administrator use to locate all files in the /var/log directory that have been modified within the last 7 days?

A.ls -lt /var/log | head -n 7
B.grep -mtime -7 /var/log
C.locate -mtime -7 /var/log
D.find /var/log -mtime -7
AnswerD

The -mtime -7 predicate matches files whose data was modified less than seven days ago, and find recurses through /var/log automatically. This directly satisfies the constraint of locating all files in that directory modified within the last 7 days.

Why this answer

The find command with -mtime -7 finds files modified less than 7 days ago. The other options are either incorrect or not suitable for this task.

30
MCQhard

An administrator needs to monitor a service's log output and wants systemd to capture the output of a specific service unit into the journal, tagged so it can be filtered by the unit name. The administrator also wants to limit how much disk space the journal may consume so it does not fill the root filesystem. Which configuration accomplishes both goals?

A.Set RuntimeMaxUse in journald.conf and add StandardOutput=file:/var/log/report.log to the service unit
B.Set Storage=none in journald.conf and add StandardOutput=syslog to the service unit
C.Set MaxLevelStore in journald.conf and add StandardError=null to the service unit
D.Set SystemMaxUse in /etc/systemd/journald.conf and ensure the service logs to the journal via StandardOutput=journal in its unit file
AnswerD

journald collects service output when a unit uses StandardOutput=journal, and entries are tagged with the unit's identifier so journalctl -u can filter them. Setting SystemMaxUse in journald.conf caps the persistent journal's disk consumption, preventing it from filling the root filesystem. Together these satisfy both the tagging and size-limit requirements.

Why this answer

Capturing a service's output in the journal with unit tagging requires the unit to send output to the journal, and journald limits total disk usage through SystemMaxUse in journald.conf. Filtering by unit then works with journalctl -u. Disabling storage, redirecting output to files, or limiting only the runtime journal fails to both capture and cap the data as required.

Exam trap

The trap here is confusing runtime-only journal limits such as RuntimeMaxUse with persistent limits like SystemMaxUse, and assuming file redirection still populates the journal.

31
MCQmedium

A technician needs to check which package provides the file /usr/bin/foo on a CentOS 8 system. Which command should be used?

A.rpm -qf /usr/bin/foo
B.rpm -V /usr/bin/foo
C.rpm -qi /usr/bin/foo
D.rpm -ql /usr/bin/foo
AnswerA

The rpm query-file option maps an installed file path back to the package that owns it, reading the local RPM database. On CentOS 8 this directly answers which package provides /usr/bin/foo, satisfying the stem's requirement without needing repository metadata.

Why this answer

On RPM-based systems, rpm -qf queries the package that owns a given file.

32
MCQmedium

Which command would display the disk usage of each file and directory in /home in a human-readable format, but only showing one level deep?

A.du -h --max-depth=1 /home
B.du -hs /home
C.du -h /home
D.df -h /home
AnswerA

`du -h --max-depth=1 /home` satisfies both constraints: `-h` converts block counts to human-readable units (K, M, G), while `--max-depth=1` limits recursion to the immediate children of /home, excluding deeper subdirectories. This matches the requirement for per-file and per-directory usage at exactly one level.

Why this answer

du -h --max-depth=1 /home shows human-readable sizes for each item one level deep.

33
MCQeasy

A Linux administrator needs to view the contents of a compressed log file without decompressing it. Which command should be used?

A.zcat
B.cat
C.bzcat
D.gunzip
AnswerA

zcat streams the contents of gzip-compressed files straight to standard output, decompressing on the fly in memory. This satisfies the requirement to read the log without first running gunzip and creating an uncompressed copy on disk.

Why this answer

zcat is the correct command because it decompresses and displays the contents of files compressed with gzip (or compress) to standard output without creating a decompressed file on disk. This allows viewing compressed logs directly, which is essential for troubleshooting without modifying the original file. It is functionally equivalent to 'gzip -dc' or 'gunzip -c'.

Exam trap

The trap here is confusing zcat with other decompression tools like bzcat or gunzip, or assuming cat can display compressed data. Candidates must remember that zcat is specifically for gzip-compressed files and does not create a decompressed file on disk.

How to eliminate wrong answers

Option B is wrong because cat simply outputs the raw compressed binary data, which appears as unreadable garbage. Option C is wrong because bzcat is used for bzip2-compressed files, not gzip-compressed files; using it on a gzip file would produce an error or garbage. Option D is wrong because gunzip decompresses the file and replaces the compressed file with an uncompressed one on disk, which is not viewing without decompressing.

34
MCQeasy

Which command displays the current default umask value for a user?

A.chmod
B.set
C.umask
D.ls -l
AnswerC

Running `umask` with no arguments prints the current file-mode creation mask for the invoking shell, expressed in octal (for example 0022). This directly satisfies the stem's requirement to display the default umask value, since the command reads and reports the setting without modifying it.

Why this answer

The umask command, when run without arguments, prints the current file-mode creation mask for the shell session. This mask determines which permission bits are removed from newly created files and directories.

Exam trap

XK0-006 often tests the distinction between commands that modify permissions (chmod) and commands that display or set the default creation mask (umask) — candidates confuse viewing permissions with viewing the umask.

How to eliminate wrong answers

Option A is wrong because chmod changes permissions on existing files; it does not display the umask. Option B is wrong because set (or set -o) displays shell options and positional parameters, not the umask. Option D is wrong because ls -l lists file details including permissions, but it does not show the umask value.

35
MCQmedium

A Linux administrator notices that the /home directory is running low on space. They need to identify which user directories are consuming the most disk space. Which command will display the total disk usage of each immediate subdirectory under /home, in human-readable format, sorted by size?

A.du -sh /home/* | sort -h
B.ls -lS /home
C.df -h /home
D.find /home -type f -size +100M
AnswerA

The du command estimates file space usage. The -s flag summarizes each argument (here, each subdirectory via the glob), and -h prints sizes in human-readable units. Piping to sort -h orders the output numerically by human-readable size, so the largest directories appear last. This directly answers the need to find which user directories consume the most space.

Why this answer

The du command with -s and -h summarizes each specified directory in human-readable units; using a glob for immediate subdirectories and piping to sort -h orders them by size. This gives a clear ranking of which user directories consume the most space, directly addressing the low-space issue. Other tools either report filesystem-level totals or list files without per-directory aggregation.

Exam trap

The trap here is confusing filesystem-level usage reported by df with per-directory usage reported by du, or assuming ls -l shows recursive directory sizes.

36
MCQmedium

A Linux administrator needs to configure a system to automatically mount an NFS share at /mnt/data during boot. The NFS server is 192.168.1.100 exporting /export/data. Which file should the administrator edit to add the appropriate entry?

A./etc/nfs.conf
B./etc/fstab
C./etc/mtab
D./etc/exports
AnswerB

The /etc/fstab file is the standard configuration file for static filesystem mounts, including network filesystems like NFS. Adding an entry such as '192.168.1.100:/export/data /mnt/data nfs defaults 0 0' ensures the share is mounted automatically at boot. The systemd mount units generated from fstab handle the actual mounting, making this the correct and persistent method.

Why this answer

To ensure an NFS share is mounted automatically at boot, the administrator must add an entry to /etc/fstab. This file contains static filesystem information that systemd uses to generate mount units. The entry includes the server export, local mount point, filesystem type, and options.

Other files like /etc/mtab or /etc/nfs.conf serve different purposes and do not control persistent mounts.

Exam trap

The trap here is confusing client-side mount configuration with server-side export configuration, leading to editing /etc/exports instead of /etc/fstab.

37
MCQeasy

Which directory in the Filesystem Hierarchy Standard (FHS) contains variable data such as logs and spool files?

A./opt
B./etc
C./var
D./tmp
AnswerC

/var holds variable data that changes during normal operation, including system logs under /var/log and print spool files under /var/spool. This directly satisfies the stem's requirement for the FHS directory designated for variable data, distinguishing it from static directories such as /usr and /etc.

Why this answer

/var is the correct directory because the Filesystem Hierarchy Standard (FHS) designates /var for variable data files that are expected to change in size and content as the system runs, such as logs, spool files, and temporary files. This includes /var/log for system logs and /var/spool for print and mail queues. It is distinct from static data like binaries or configuration.

Exam trap

The trap is confusing /var with /tmp or /etc. Candidates might think logs are in /tmp because they are temporary, but /tmp is for short-lived files, while /var is for persistent variable data. Also, /etc is for configuration, not logs.

How to eliminate wrong answers

Option A is wrong because /opt is for optional application software packages, not variable data. Option B is wrong because /etc is for host-specific system configuration files, which are typically static. Option D is wrong because /tmp is for temporary files that may be cleared on reboot, not for persistent variable data like logs.

38
MCQmedium

An administrator needs to permanently mount an ext4 filesystem on /dev/sdb1 to the /data directory. Which file must be edited to ensure the mount persists across reboots?

A./etc/sysconfig/network
B./etc/default/grub
C./etc/fstab
D./etc/mtab
AnswerC

Editing /etc/fstab defines a persistent mount entry, satisfying the requirement that the ext4 filesystem on /dev/sdb1 survives reboots. Each line specifies the device, mount point (/data), filesystem type and options, which the system reads at boot to mount automatically, unlike temporary mounts made with the mount command.

Why this answer

The /etc/fstab file is the system's static filesystem table, read by systemd or the init scripts during boot to mount filesystems automatically. To make a mount persistent, you add an entry specifying the device (/dev/sdb1), mount point (/data), filesystem type (ext4), and options (e.g., defaults). This ensures the kernel mounts the filesystem on every reboot without manual intervention.

Exam trap

The trap here is confusing runtime mount information (/etc/mtab) with persistent configuration (/etc/fstab), or assuming network or GRUB config files affect filesystem mounts.

How to eliminate wrong answers

Option A is wrong because /etc/sysconfig/network configures network settings on some distributions (like RHEL) and has nothing to do with filesystem mounts. Option B is wrong because /etc/default/grub holds GRUB bootloader configuration, such as kernel command-line parameters, not mount definitions. Option D is wrong because /etc/mtab is a dynamic, read-only file maintained by the kernel that lists currently mounted filesystems; editing it does not affect boot-time mounts and is typically a symlink to /proc/self/mounts on modern systems.

39
MCQhard

A Linux server has a logical volume that is running out of space. The administrator extends the underlying volume group by adding a new physical volume, then extends the logical volume and resizes the filesystem. Which command should be used to resize the ext4 filesystem after extending the logical volume?

A.xfs_growfs /dev/vg0/lv_data
B.resize2fs /dev/vg0/lv_data
C.lvextend -r /dev/vg0/lv_data
D.vgextend vg0 /dev/sdb1
AnswerB

resize2fs is the correct utility to resize ext2, ext3, and ext4 filesystems. After extending the logical volume with lvextend, running resize2fs on the device path resizes the filesystem to use the additional space. It can be run without unmounting if the filesystem supports online resizing.

Why this answer

After extending the logical volume, the ext4 filesystem must be resized to use the new space. The resize2fs command is designed for this purpose and can resize ext4 filesystems online. It is the correct tool after lvextend.

Exam trap

The trap here is confusing the logical volume extension with filesystem resizing; lvextend only extends the LV, not the filesystem.

40
MCQmedium

A system administrator notices that a process with PID 1234 is consuming excessive CPU. The administrator wants to terminate this process gracefully. Which command should be used?

A.killall 1234
B.kill 1234
C.pkill -9 1234
D.kill -9 1234
AnswerB

`kill 1234` sends SIGTERM (signal 15) by default, which requests graceful termination and lets the process run cleanup handlers before exiting. This satisfies the stem's requirement to terminate PID 1234 gracefully, unlike `kill -9`, which sends SIGKILL and terminates immediately without cleanup.

Why this answer

The `kill` command sends SIGTERM (signal 15) by default, which requests that the process terminate gracefully — allowing it to save state, close file handles, and clean up before exiting. Since the administrator wants a graceful termination, `kill 1234` is the correct choice because it targets the specific PID with the default SIGTERM signal.

Exam trap

The trap here is conflating 'terminate' with 'force kill' — candidates see 'terminate' and reach for `-9`, but the word 'gracefully' is the key qualifier that points to the default SIGTERM.

How to eliminate wrong answers

Option A is wrong because `killall` takes a process name, not a PID, so `killall 1234` would look for a process literally named '1234' and fail. Option C is wrong because `pkill -9 1234` sends SIGKILL (signal 9) — an immediate, non-graceful termination — and `pkill` also matches by name/pattern rather than PID. Option D is wrong because `kill -9 1234` sends SIGKILL, which forcibly terminates the process without allowing cleanup, contradicting the 'gracefully' requirement.

41
MCQeasy

A Linux administrator needs to change the permissions of a file to allow the owner to read and write, the group to read only, and others to have no access. Which chmod command should be used?

A.chmod 640 file
B.chmod 600 file
C.chmod 755 file
D.chmod 644 file
AnswerA

chmod 640 sets the owner bits to read and write (4+2=6), the group bits to read only (4), and others to none (0), exactly matching the required permission set. The three-digit octal notation maps each digit to user, group, and other classes respectively, satisfying the stem's constraint.

Why this answer

The symbolic representation rw-r----- corresponds to octal 640. rw- = 4+2+0=6, r-- = 4+0+0=4, --- = 0+0+0=0.

42
MCQeasy

Which command displays the amount of free and used disk space on all mounted file systems in a human-readable format?

A.du -h /
B.lsblk -h
C.mount -h
D.df -h
AnswerD

`df -h` reports free and used space for every mounted file system, satisfying the "all mounted file systems" constraint. The `-h` flag converts block counts into human-readable units such as gigabytes, meeting the formatting requirement. Unlike `du`, which measures directory consumption, `df` queries file system statistics directly.

Why this answer

The df command reports file system disk space usage, and the -h flag renders sizes in human-readable units (K, M, G). Running df -h shows all mounted file systems with total, used, available space, and mount point. This is the standard Linux utility for checking free and used disk space.

Exam trap

XK0-006 often tests the confusion between df (file system free space) and du (directory/file usage); candidates see '-h' and 'disk' in the question and pick du because it also measures disk usage.

How to eliminate wrong answers

Option A is wrong because du -h / estimates disk usage of files and directories under a path, not the free/used space of mounted file systems. Option B is wrong because lsblk lists block devices and their partitions/topology; the -h flag is not a human-readable size switch for lsblk (it shows help), and it does not report file system usage. Option C is wrong because mount -h prints help for the mount command and does not display disk space statistics at all.

43
MCQmedium

Which command displays the number of lines, words, and characters in a file?

A.wc file.txt
B.wc -w file.txt
C.cat file.txt | wc -l
D.stat file.txt
AnswerA

`wc file.txt` outputs newline, word, and byte counts in a single pass, directly satisfying the stem's requirement for all three metrics. Unlike `cat`, `grep -c`, or `sed`, which report only lines or content, `wc` is purpose-built for counting, so it returns the exact line, word, and character totals requested.

Why this answer

The `wc` command without any options displays the number of lines, words, and characters in a file, in that order. By default, `wc` counts newline characters (lines), whitespace-delimited tokens (words), and bytes (characters) in the specified file. This makes option A the correct choice for displaying all three counts.

Exam trap

The trap here is that candidates often confuse the default behavior of `wc` (which shows all three counts) with options like `-w` or `-l` that only show one metric, or they mistakenly think `stat` provides line/word counts.

How to eliminate wrong answers

Option B is wrong because `wc -w` only counts the number of words in the file, not lines or characters. Option C is wrong because `cat file.txt | wc -l` only counts the number of lines (newline characters) in the file, not words or characters. Option D is wrong because `stat file.txt` displays file metadata such as size, permissions, and timestamps, but does not count lines, words, or characters.

44
MCQeasy

A user wants to change the permissions of a file to give the owner full control, the group read and execute, and others no access. Which of the following chmod commands will achieve this?

A.chmod 750 file
B.chmod 700 file
C.chmod 770 file
D.chmod 755 file
AnswerA

`chmod 750` encodes owner read/write/execute (7), group read/execute (5), and others no access (0), matching the requested permission set exactly. The three octal digits map directly to user, group, and other classes, so this single command satisfies every constraint in the scenario.

Why this answer

The numeric chmod mode 750 translates to owner=7 (read+write+execute = 4+2+1), group=5 (read+execute = 4+1), and others=0 (no access). This exactly matches the requirement: owner full control, group read and execute, others no access.

Exam trap

XK0-006 often tests the octal-to-permission mapping, so candidates who confuse the group and others digits (e.g., picking 755 or 770) fail to match the exact requirement of group read/execute and others no access.

How to eliminate wrong answers

Option B (700) is wrong because it gives the group no permissions at all, but the requirement is group read and execute. Option C (770) is wrong because it gives others read, write, and execute, which violates the 'others no access' requirement. Option D (755) is wrong because it gives others read and execute, but the requirement is others no access.

45
MCQeasy

A junior administrator needs to change the ownership of the file /var/www/html/index.html from user 'www-data' to user 'apache' and group 'apache'. Which command will accomplish this?

A.usermod -g apache www-data /var/www/html/index.html
B.chown apache:apache /var/www/html/index.html
C.chmod apache:apache /var/www/html/index.html
D.chgrp apache /var/www/html/index.html
AnswerB

chown changes file owner and group. The syntax user:group sets both simultaneously. Using apache:apache sets the owner to apache and the group to apache, exactly as required. This is the standard way to change both ownership attributes in one command, and it requires appropriate privileges (usually root).

Why this answer

The chown command with user:group syntax changes both the owner and group of a file. Specifying apache:apache sets the owner and group to apache, fulfilling the requirement. Other commands either modify permissions, change only the group, or modify user account properties rather than file ownership.

Exam trap

The trap here is mixing up chmod (permissions) with chown (ownership), or using chgrp when both owner and group must change.

46
MCQmedium

A user reports that they cannot access a file because permission is denied. The file's permissions are -rwsr-xr-x. What special permission is set?

A.No special permission
B.SUID
C.Sticky bit
D.SGID
AnswerB

The `s` in the owner execute position of `-rwsr-xr-x` denotes SUID (Set User ID). When executed, the file runs with the owner's privileges rather than the invoking user's, satisfying the stem's requirement to identify the special permission set on this file.

Why this answer

The permissions string `-rwsr-xr-x` shows an 's' in the owner's execute position, which is the SUID (Set User ID) bit. When SUID is set on an executable, the process runs with the effective UID of the file's owner rather than the invoking user — commonly used by utilities like `passwd` to allow normal users to modify protected files.

Exam trap

The trap is misreading which position the 's' occupies — candidates who don't carefully distinguish owner vs. group execute positions will confuse SUID with SGID.

How to eliminate wrong answers

Option A is wrong because the 's' in the owner execute position is itself the special permission indicator — there is clearly a special bit set. Option C is wrong because the sticky bit appears as a 't' in the other/execute position (e.g., `drwxrwxrwt` on /tmp), not as an 's' in the owner position. Option D is wrong because SGID appears as an 's' in the group execute position (e.g., `-rwxr-sr-x`), not the owner position.

47
MCQmedium

Which of the following commands will display the last 10 lines of a log file and also output new lines as they are appended?

A.head -f logfile
B.less +F logfile
C.tail -f logfile
D.cat logfile
AnswerC

The -f flag makes tail follow the file descriptor, printing appended lines as they are written rather than exiting after the last 10. This satisfies both requirements: the default last-10-lines display plus continuous live output.

Why this answer

The `tail -f logfile` command displays the last 10 lines of the file by default and then continues to monitor the file for new lines, outputting them as they are appended. The `-f` (follow) option keeps the file open and polls for changes, making it the standard tool for real-time log monitoring.

Exam trap

The trap here is that candidates may confuse `tail -f` with `less +F` (which also works but uses a different syntax) or mistakenly think `head` can follow a file, but the exam expects precise knowledge of the `tail -f` command as the standard for real-time log viewing.

How to eliminate wrong answers

Option A is wrong because `head -f` is not a valid command; `head` does not support a `-f` flag, and even if it did, `head` reads from the beginning of the file, not the end. Option B is wrong because `less +F` does not exist; the correct syntax to follow a file in `less` is `less +F` (uppercase F) which enters follow mode, but the lowercase `+F` is invalid and will cause an error. Option D is wrong because `cat logfile` simply outputs the entire file content to stdout and does not provide any real-time monitoring or line limiting.

48
MCQhard

A system administrator runs 'umask 027' in a Bash shell. What will be the default permissions for a new directory created in that shell? (Assume no other umask changes.)

A.rwxrwxr-x (775)
B.rwxrwxrwx (777)
C.rw-rw-r-- (664)
D.rwxr-x--- (750)
AnswerD

Correct: 777 - 027 = 750.

Why this answer

The umask value 027 subtracts permissions from the base 777 for directories. 777 minus 027 equals 750, which translates to rwxr-x---. The owner gets full permissions (rwx), the group gets read and execute (r-x), and others get no permissions (---).

Exam trap

CompTIA often tests the distinction between file and directory base permissions (666 vs 777) and the fact that umask subtracts from the base, not from a fixed value like 755.

How to eliminate wrong answers

Option A is wrong because it represents permissions 775 (rwxrwxr-x), which would result from a umask of 002, not 027. Option B is wrong because it represents permissions 777 (rwxrwxrwx), which would result from a umask of 000, not 027. Option C is wrong because it represents permissions 664 (rw-rw-r--), which is the default for files (base 666) with a umask of 002, not for directories with umask 027.

49
MCQhard

A Linux administrator is troubleshooting a systemd service that fails to start. The service unit file is located at /etc/systemd/system/myservice.service. After editing the unit file, the administrator runs systemctl start myservice, but the service still uses the old configuration. Which command should be run to ensure systemd reloads the modified unit file?

A.systemctl restart myservice
B.systemctl daemon-reload
C.systemctl reenable myservice
D.systemctl reload myservice
AnswerB

systemctl daemon-reload reloads systemd manager configuration, including all unit files. After editing a unit file, this command is necessary so systemd picks up changes. Without it, systemd continues using the cached version, causing the service to run with old settings.

Why this answer

After modifying a systemd unit file, the systemd manager must reload its configuration to recognize the changes. The systemctl daemon-reload command performs this reload, ensuring subsequent start or restart operations use the updated unit file.

Exam trap

The trap here is assuming that restarting the service is enough to apply unit file changes; systemd caches unit files until daemon-reload is executed.

50
Multi-Selecthard

A system administrator is investigating a performance issue and wants to view kernel-related messages. Which three commands can be used to access kernel ring buffer messages? (Choose three.)

Select 3 answers
A.tail -f /var/log/syslog
B.dmesg
C.cat /var/log/kern.log
D.journalctl -k
E.systemctl status
AnswersB, C, D

`dmesg` reads the kernel ring buffer directly, satisfying the requirement to view kernel-related messages. It exposes boot-time hardware detection, driver initialisation and runtime kernel warnings, and supports filtering by facility or severity. Unlike journal-based tools, it needs no persistent logging daemon, so it works even when systemd-journald is unavailable.

Why this answer

Option B (dmesg) is correct because dmesg directly reads and prints the kernel ring buffer, which is exactly the kernel-related message store the administrator needs. Option C (cat /var/log/kern.log) is correct because on many Linux distributions the kernel ring buffer messages are persisted to /var/log/kern.log, so reading that file exposes kernel messages. Option D (journalctl -k) is correct because the -k (or --dmesg) flag restricts systemd journal output to kernel messages only, providing access to kernel ring buffer content.

Option A (tail -f /var/log/syslog) is not correct here because syslog is a general system log that may include kernel messages only indirectly and is not the kernel ring buffer itself. Option E (systemctl status) is not correct because it reports the status of systemd units and does not display kernel ring buffer messages.

Exam trap

XK0-006 often tests whether candidates distinguish kernel-specific log access (dmesg, journalctl -k, /var/log/kern.log) from general system logs (/var/log/syslog) and service status commands (systemctl status) — picking syslog because it 'contains kernel messages' is the classic mistake.

51
MCQhard

During the boot process, after the kernel is loaded and the initramfs is executed, which component is responsible for starting the user-space services and managing the system state?

A.initramfs
B.systemd
C.GRUB2
D.Kernel
AnswerB

Systemd takes over as PID 1 once the kernel hands off from initramfs, mounting remaining filesystems and activating units in dependency order to reach the requested target. It satisfies the stem's requirement for the component that starts user-space services and manages system state after initramfs execution.

Why this answer

Systemd is the init system that starts services and manages targets. GRUB2 is the bootloader that loads the kernel. The kernel itself initializes hardware.

Initramfs is an initial root filesystem used to load drivers.

52
MCQeasy

An administrator notices that the /var partition on a production server is nearly full and wants to determine which subdirectories consume the most space before deleting anything. The administrator has root privileges and wants a human-readable summary of each immediate subdirectory under /var, one line per directory. Which command accomplishes this?

A.du -sh /var/*
B.df -h /var
C.find /var -size +100M
D.ls -lhR /var
AnswerA

The du command estimates disk usage, the -s flag summarizes each argument into a single total, and -h produces human-readable sizes. Expanding /var/* passes each immediate subdirectory to du, yielding one summarized line per subdirectory. This directly identifies the largest consumers under /var, which is exactly what the administrator needs before deleting files.

Why this answer

To see which directories under /var consume the most space, du with -s and -h summarizes each argument passed via shell glob expansion, producing one human-readable line per immediate subdirectory. This gives an actionable ranking of space consumers. Filesystem-level tools like df and metadata listings like ls do not aggregate directory totals, so they cannot answer the question.

Exam trap

The trap here is confusing df, which reports filesystem capacity, with du, which reports directory consumption.

53
MCQmedium

An administrator needs to find all files in /var/log that have been modified within the last 2 days. Which find command should be used?

A.find /var/log -mtime -2
B.find /var/log -mtime +2
C.find /var/log -atime -2
D.find /var/log -ctime 2
AnswerA

-mtime -2 matches files whose modification time is less than two days ago, covering the last 48 hours. The negative argument is the axis that matters: -mtime +2 would instead return files older than two days.

Why this answer

The `-mtime -2` option in `find` matches files whose data was last modified less than 2 days ago (i.e., within the last 48 hours). The minus sign means 'less than', so `-mtime -2` correctly finds files modified in the last 2 days. This is the standard way to search by modification time in Linux.

Exam trap

The trap here is confusing the sign convention: candidates often think `-mtime +2` means 'within 2 days' when it actually means 'more than 2 days ago', and they may also mix up `-mtime` with `-atime` or `-ctime`.

How to eliminate wrong answers

Option B is wrong because `-mtime +2` matches files modified more than 2 days ago (older than 48 hours), which is the opposite of what is needed. Option C is wrong because `-atime -2` checks access time (when the file was last read), not modification time; the administrator specifically asked for files modified within the last 2 days. Option D is wrong because `-ctime 2` matches files whose status (inode metadata) changed exactly 2 days ago, not within the last 2 days, and it also uses change time rather than modification time.

54
MCQeasy

Which directory in the FHS contains essential user command binaries that are needed in single-user mode?

A./usr/bin
B./sbin
C./opt/bin
D./bin
AnswerD

/bin holds essential user command binaries required for single-user mode and system repair, such as ls, cp and cat. It is distinct from /sbin, which holds system administration binaries, and /usr/bin, which holds non-essential user commands.

Why this answer

The /bin directory, as defined by the Filesystem Hierarchy Standard (FHS), contains essential user command binaries (e.g., ls, cp, mv) that are required for booting, repairing, and operating the system in single-user mode. Single-user mode mounts only the root filesystem, so /bin must be on the root partition to provide these critical utilities without relying on other filesystems like /usr.

Exam trap

The trap here is that candidates confuse /sbin with /bin, assuming all essential binaries are in /sbin, but /sbin is specifically for system administration tools, while /bin holds the user command binaries required in single-user mode.

How to eliminate wrong answers

Option A is wrong because /usr/bin contains non-essential user binaries that are not guaranteed to be available in single-user mode, as /usr may be a separate filesystem that is not mounted during early boot or recovery. Option B is wrong because /sbin contains system administration binaries (e.g., fdisk, init) intended for system maintenance, not general user commands, and is separate from the user command binaries specified in the question. Option C is wrong because /opt/bin is not a standard FHS directory; /opt is reserved for add-on application software packages, and its binaries are not part of the essential system binaries needed in single-user mode.

55
Multi-Selecthard

A Linux administrator needs to identify which of the following filesystems are journaling filesystems commonly used in Linux. (Choose three.)

Select 3 answers
A.swap
B.ext4
C.FAT32
D.btrfs
E.xfs
AnswersB, D, E

ext4 is a journaling filesystem: it maintains a journal recording pending metadata changes, so it is commonly used on Linux and satisfies the requirement to identify journaling filesystems. Its predecessor ext3 also journals, but ext4 adds extents and larger volume support.

Why this answer

ext4 (B) is a journaling filesystem that maintains a journal to record metadata changes before committing them, enabling fast recovery after crashes, and it is the default on many Linux distributions. btrfs (D) is a copy-on-write filesystem with built-in journaling-like consistency via its COW transaction mechanism, widely used in Linux for snapshots and checksumming. xfs (E) is a high-performance journaling filesystem developed by SGI and commonly used in Linux for large files and parallel I/O. swap (A) is not a filesystem for storing files but a raw swap space used for virtual memory paging, and FAT32 (C) is a non-journaling filesystem from the FAT family that lacks journaling and metadata consistency features.

Exam trap

XK0-006 often tests the distinction between journaling filesystems and non-journaling ones (FAT32) or non-filesystems (swap), catching candidates who assume any Linux storage technology counts as a journaling filesystem.

56
MCQeasy

Which of the following directories is defined by the Filesystem Hierarchy Standard (FHS) as containing essential user command binaries that need to be available in single-user mode?

A./sbin
B./opt/bin
C./usr/bin
D./bin
AnswerD

/bin holds essential user command binaries required for single-user mode, such as ls, cp and sh. The FHS reserves it precisely for binaries needed before /usr is mounted, satisfying the single-user availability constraint. Other directories like /usr/bin hold non-essential binaries that may depend on separate mounts.

Why this answer

/bin contains essential command binaries required for booting and single-user mode.

57
Multi-Selecthard

A Linux administrator is troubleshooting a system that is running out of disk space on the root filesystem. The administrator needs to identify which directories are consuming the most space. Which TWO commands can be used to find the largest directories? (Choose two.)

Select 2 answers
A.ls -lR /
B.ncdu /
C.du -sh /* | sort -rh | head -n 10
D.df -h
E.find / -type d -size +100M
AnswersB, C

ncdu is an interactive disk usage analyzer that scans a directory and displays sizes in a navigable interface. Running ncdu / will analyze the entire root filesystem and allow the administrator to drill down into large directories, making it an excellent tool for this scenario.

Why this answer

The commands du -sh /* | sort -rh | head -n 10 and ncdu / are both effective for identifying the largest directories. The du pipeline provides a quick text-based summary, while ncdu offers an interactive interface for exploration. Both directly address the need to find space-consuming directories.

Exam trap

The trap here is assuming df -h shows directory sizes, but it only shows filesystem-level usage, not per-directory breakdown.

58
MCQmedium

A system administrator wants to find all files in /var/log that have been modified in the last 7 days and are larger than 100MB. Which command should be used?

A.find /var/log -mtime +7 -size +100M
B.find /var/log -atime -7 -size +100M
C.find /var/log -mtime -7 -size +100M
D.find /var/log -mtime -7 -size -100M
AnswerC

The `-mtime -7` predicate matches files modified within the last seven days, while `-size +100M` filters those exceeding 100MB, both applied to the `/var/log` path. Combining these tests with implicit AND logic satisfies the stem's dual constraints of recent modification and large size in a single traversal.

Why this answer

The find command with -mtime -7 matches files modified within the last 7 days (the minus sign means 'less than 7 days ago'), and -size +100M matches files larger than 100MB (the plus sign means 'greater than'). This combination precisely satisfies both conditions.

Exam trap

XK0-006 often tests the sign convention in find time and size predicates — candidates frequently invert -mtime -7 and -mtime +7 or confuse -atime with -mtime.

How to eliminate wrong answers

Option A is wrong because -mtime +7 matches files modified more than 7 days ago, which is the opposite of the requirement. Option B is wrong because -atime -7 checks access time, not modification time — reading a file updates atime, so it would return files that were merely read, not modified. Option D is wrong because -size -100M matches files smaller than 100MB, the reverse of what is needed.

59
MCQeasy

Which command is used to query the status of a service managed by systemd?

A.journalctl -u servicename
B.service servicename status
C.systemctl list-units --type=service
D.systemctl status servicename
AnswerD

systemctl is the control interface for systemd units, and its status subcommand reports whether the named service is active, inactive or failed, plus recent log lines. This directly satisfies the requirement to query a systemd-managed service's current state.

Why this answer

systemctl status shows whether a service is active, enabled, and recent log entries.

60
MCQmedium

A process is consuming excessive CPU and needs to be stopped immediately. The process ID is 4582. Which command should be used?

A.kill -9 4582
B.kill -1 4582
C.kill -STOP 4582
D.kill -15 4582
AnswerA

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 4582 immediately without waiting for cleanup. This satisfies the stem's requirement to stop the runaway process at once, unlike SIGTERM, which the process may handle or defer.

Why this answer

The `kill -9 4582` command sends SIGKILL (signal 9) to process ID 4582, which forcibly terminates the process immediately without allowing it to clean up. This is the correct choice when a process is consuming excessive CPU and must be stopped immediately, as SIGKILL cannot be caught or ignored.

Exam trap

The trap is thinking SIGTERM (15) is immediate; candidates often pick `kill -15` as the default, but the question specifies 'immediately', which requires SIGKILL (9).

How to eliminate wrong answers

Option B is wrong because `kill -1` sends SIGHUP (signal 1), which typically causes a process to reload configuration or terminate, but it can be caught or ignored. Option C is wrong because `kill -STOP` sends SIGSTOP, which pauses the process but does not terminate it; it remains in memory. Option D is wrong because `kill -15` sends SIGTERM, the default termination signal, which allows the process to perform cleanup and can be caught or ignored, so it may not stop a runaway process immediately.

61
MCQmedium

A Linux administrator needs to permanently set the system-wide umask to 027 for all users on a production server. The administrator edits /etc/profile and adds the line 'umask 027'. After rebooting, a user logs in and runs 'umask', which returns 0022. Which of the following is the most likely reason the setting did not take effect?

A.The user's shell configuration file, such as ~/.bashrc or ~/.profile, overrides the umask set in /etc/profile.
B.The umask command must be run with sudo to affect all users.
C.The umask value must be set in /etc/login.defs to apply system-wide.
D.The system needs to be rebooted for changes to /etc/profile to take effect.
AnswerA

User-specific shell initialization files like ~/.bashrc or ~/.profile are sourced after /etc/profile and can override the umask. If the user's file contains a umask command, it will take precedence. This is the most common reason a system-wide umask in /etc/profile appears ineffective, as the user's environment resets the value during login.

Why this answer

The umask is set per process and inherited. System-wide defaults in /etc/profile apply to login shells, but user-specific files like ~/.bashrc or ~/.profile are sourced later and can override the umask. Since the user's umask returned 0022, it indicates a user-level configuration is taking precedence.

To enforce a system-wide umask, administrators must ensure user files do not override it or use mechanisms like pam_umask.

Exam trap

The trap here is assuming that editing /etc/profile alone guarantees a system-wide umask, overlooking that per-user shell configuration files are sourced afterward and can override it.

62
MCQmedium

An administrator wants to ensure a service starts automatically at boot on a systemd-based system. Which command should be used?

A.systemctl enable service
B.systemctl start service
C.systemctl status service
D.systemctl reload service
AnswerA

`systemctl enable service` creates the symlinks that pull the unit into the boot transaction, so the service starts automatically at every boot on a systemd-based host. It satisfies the stem's requirement directly; `start` only launches it for the current session and does not persist across reboots.

Why this answer

On systemd-based systems, 'systemctl enable <service>' creates the necessary symlinks (typically in /etc/systemd/system/) so that the service is started automatically at boot. It does not start the service immediately; it only configures it for future boots.

Exam trap

XK0-006 often tests whether candidates confuse 'enable' (boot persistence) with 'start' (immediate start), leading them to pick 'start' when the question asks for automatic startup at boot.

How to eliminate wrong answers

Option B is wrong because 'systemctl start <service>' starts the service immediately but does not configure it to start at boot. Option C is wrong because 'systemctl status <service>' only displays the current status of the service, it does not change its boot behavior. Option D is wrong because 'systemctl reload <service>' reloads the service's configuration without restarting it, and does not affect boot-time startup.

63
MCQmedium

A Linux administrator needs to create a new user account named 'jsmith' with a home directory /home/jsmith and the default shell /bin/bash. Which command should the administrator use?

A.useradd -m -s /bin/bash jsmith
B.passwd jsmith
C.usermod -aG jsmith
D.adduser jsmith
AnswerA

useradd -m creates the user's home directory if it does not exist, and -s /bin/bash sets the login shell. This command creates the account with the specified home directory and shell. It is the standard low-level utility for adding users on most Linux distributions and meets all requirements in the scenario.

Why this answer

The correct command is useradd -m -s /bin/bash jsmith, which creates the user, makes the home directory, and sets the login shell to /bin/bash. This is the most direct and portable way to create a user with specific attributes. Other commands either modify existing users, set passwords, or are interactive and less precise.

Exam trap

The trap here is confusing useradd with adduser; adduser is interactive and may not allow specifying the shell directly, while useradd is scriptable and precise.

64
MCQmedium

An administrator wants to find all files in /var/log that have been modified within the last 2 days and have a .log extension. Which command should be used?

A.find /var/log -mtime 2 -name *.log
B.find /var/log -type f -mtime -2 -name "*.log"
C.locate --mtime -2 *.log /var/log
D.ls -la /var/log | grep "\.log$" | head -20
AnswerB

The `-mtime -2` test matches files modified less than two days ago, satisfying the recency constraint, while `-name "*.log"` filters by extension and `-type f` excludes directories. Combining these predicates with `find` in `/var/log` returns exactly the required set in one pass.

Why this answer

The find command with -mtime -2 finds files modified less than 2 days ago, and -name '*.log' matches the extension.

65
MCQeasy

Which command is used to create a symbolic link named 'link' pointing to the file 'original'?

A.symlink original link
B.ln -s link original
C.ln original link
D.ln -s original link
AnswerD

The -s flag creates a symbolic link rather than a hard link, and the syntax places the target (original) before the link name (link). This produces a symlink named 'link' pointing to 'original' as required.

Why this answer

ln -s creates a symbolic link.

66
MCQmedium

An administrator wants to grant a specific user, 'jdoe', read and write access to a file that is owned by root:root with permissions 640. The administrator does not want to change the file's owner or group. Which approach should be used?

A.Use setfacl -m u:jdoe:rw file
B.Change file owner to jdoe
C.Use chmod o+rw file
D.Add jdoe to the root group
AnswerA

setfacl -m u:jdoe:rw adds a named user entry to the file's access control list, granting jdoe read and write access. This satisfies the constraint of not altering the file's owner or group, which chmod and chown would change.

Why this answer

POSIX ACLs allow granting permissions to specific users or groups without altering the file's owner or group. The command 'setfacl -m u:jdoe:rw file' adds an ACL entry giving jdoe read and write access while leaving root:root ownership and the 640 mode intact. This is the standard, least-disruptive approach for per-user access on a shared file.

Exam trap

XK0-006 often tests whether candidates reach for chmod or group membership when the requirement is per-user access without changing ownership — the trap is over-granting with 'o+rw' or 'add to root group'.

How to eliminate wrong answers

Option B is wrong because changing the file owner to jdoe removes root's ownership, which is a broader change than required and may break services or scripts that depend on root ownership. Option C is wrong because 'chmod o+rw' grants read/write to all other users on the system, not just jdoe — a serious security over-exposure. Option D is wrong because adding jdoe to the root group grants group-level access to every file owned by root:root with group permissions, which is far broader than needed and violates least privilege.

67
MCQhard

A developer creates a hard link to a file and then deletes the original file. What happens to the hard link?

A.The hard link is broken and cannot be accessed.
B.The hard link still contains the data and is accessible.
C.The hard link is automatically converted to a copy of the file.
D.The hard link becomes a symbolic link.
AnswerB

Hard links share the same inode, so deleting the original filename only removes one directory entry; the inode's link count drops but data persists. The remaining hard link still resolves to that inode and remains fully readable.

Why this answer

Hard links share the same inode; deleting the original file removes one link, but the data remains accessible via the hard link until all links are removed.

68
Multi-Selectmedium

A Linux administrator needs to schedule a backup script to run every day at 2:30 AM. Which TWO of the following methods can be used to achieve this? (Choose two.)

Select 2 answers
A.Create a systemd service with Restart=always and RestartSec=86400.
B.Use the 'at' command to schedule the script with 'at 02:30' and repeat it daily.
C.Create a cron job with the schedule '30 2 * * *' in the root crontab.
D.Add the script to /etc/cron.daily/ with a filename that starts with '02:30'.
E.Create a systemd timer unit with OnCalendar=*-*-* 02:30:00 and enable it.
AnswersC, E

A cron job with the schedule '30 2 * * *' will run the command every day at 2:30 AM. The fields represent minute, hour, day of month, month, and day of week. This is a standard and reliable method for scheduling recurring tasks on Linux. It is directly supported by the cron daemon and is easy to set up.

Why this answer

Both cron and systemd timers are valid methods for scheduling recurring tasks at specific times. A cron job with the schedule '30 2 * * *' runs daily at 2:30 AM. A systemd timer with OnCalendar=*-*-* 02:30:00 also triggers daily at that time when enabled.

These are the two correct approaches among the options.

Exam trap

The trap here is thinking that placing a script in /etc/cron.daily/ can control the exact execution time, but it cannot; the time is set by system crontab.

69
MCQeasy

A Linux administrator needs to check the available disk space on all mounted filesystems in a human-readable format. Which command should the administrator use?

A.fdisk -l
B.du -h
C.lsblk
D.df -h
AnswerD

The df command reports filesystem disk space usage, and the -h flag displays sizes in human-readable units such as GB and MB. This directly answers the need to view available space on all mounted filesystems in an easily readable format. It is the standard tool for this task and is available on virtually all Linux distributions.

Why this answer

df -h is the correct command because it reports filesystem disk space usage and free space for all mounted filesystems in human-readable units. The -h flag converts sizes to GB, MB, or KB as appropriate, making the output easy to interpret. Other commands either show file sizes, partition tables, or block device topology, not free space.

Exam trap

The trap here is confusing disk usage reporting tools: df shows filesystem free space, while du shows how much space files and directories consume.

70
MCQmedium

A Linux administrator needs to create a new user account 'analyst' with a home directory at /home/analyst and the default shell set to /bin/bash. The user should also be added to the existing supplementary group 'research'. Which command will accomplish this in a single step?

A.useradd -m -s /bin/bash -G research analyst
B.groupadd research && useradd -m -s /bin/bash -g research analyst
C.usermod -m -s /bin/bash -G research analyst
D.adduser analyst -m -s /bin/bash -g research
AnswerA

The useradd command with -m creates the home directory, -s sets the login shell, and -G adds the user to the supplementary group 'research'. This single command fulfills all requirements without additional steps, making it the correct choice.

Why this answer

The useradd command with -m creates the home directory, -s specifies the shell, and -G adds the user to supplementary groups. This single command meets all specified conditions without extra steps, making it the correct solution.

Exam trap

The trap here is confusing the -g option (primary group) with -G (supplementary groups), which can lead to incorrect group membership.

71
MCQmedium

An administrator wants to start a long-running script in the background so that it continues running even after logging out. Which command should be used?

A.script.sh &
B.nohup script.sh &
C.nohup script.sh
D.bg script.sh
AnswerB

nohup makes the process immune to SIGHUP, so it survives terminal closure and logout, while the trailing & backgrounds it immediately. This satisfies the requirement that the script keeps running after the session ends, unlike a plain background job.

Why this answer

nohup (no hangup) makes the process immune to the SIGHUP signal that is sent to child processes when the controlling terminal closes on logout. Appending & backgrounds the job so the shell returns a prompt immediately. Combining both is required: nohup alone still runs in the foreground and blocks the terminal, while & alone leaves the process vulnerable to SIGHUP on logout.

Exam trap

The trap here is confusing backgrounding (&) with detaching from the terminal (nohup); candidates pick & alone and forget that SIGHUP kills the job on logout.

How to eliminate wrong answers

Option A is wrong because script.sh & only backgrounds the job; when the login shell exits it sends SIGHUP to its process group and the script is terminated. Option C is wrong because nohup script.sh runs the script in the foreground, so the administrator cannot continue using the shell and the terminal session is tied up. Option D is wrong because bg is a shell builtin that only resumes a stopped job in the background of the current shell; it does not detach the process from the terminal or protect it from SIGHUP at logout.

72
MCQmedium

An administrator wants to change the priority of a running process with PID 1234 to a lower priority (nicer). The current nice value is 0. Which command will set the nice value to 10?

A.renice 10 -p 1234
B.nice -n 10 kill 1234
C.chrt -p 10 1234
D.kill -10 1234
AnswerA

renice alters the nice value of an already-running process identified by PID, so renice 10 -p 1234 raises niceness from 0 to 10, lowering scheduling priority. The -p flag specifies the target PID, satisfying the requirement to change a running process rather than launch a new one.

Why this answer

The `renice` command is used to alter the scheduling priority of an already running process. By default, a process starts with a nice value of 0. Running `renice 10 -p 1234` sets the nice value to 10, which is a lower priority (more 'nice') because the kernel adds this value to the dynamic priority calculation, giving the process less CPU time.

Exam trap

The Linux+ exam often tests the distinction between `renice` (for running processes) and `nice` (for launching a new process with a modified priority), and candidates may confuse `renice` with `nice` or think `kill` can change priority via signal numbers.

How to eliminate wrong answers

Option B is wrong because `nice -n 10 kill 1234` attempts to run the `kill` command with a nice value of 10, but `kill` does not change the priority of an existing process; it sends signals. Option C is wrong because `chrt -p 10 1234` sets the real-time scheduling policy and priority (via the `-p` flag with a priority value), not the nice value; `chrt` manipulates the SCHED_FIFO or SCHED_RR policy, not the conventional nice/renice mechanism. Option D is wrong because `kill -10 1234` sends signal 10 (SIGUSR1 by default on Linux) to the process, which has no effect on its nice value or scheduling priority.

73
MCQmedium

A Linux administrator needs to locate all files in the /var directory that have been modified within the last 30 minutes and are larger than 10MB. Which command accomplishes this task?

A.find /var -mmin 30 -size +10M
B.find /var -mmin -30 -size +10M
C.locate /var -mmin -30 -size +10M
D.find /var -mtime -30 -size +10M
AnswerB

The -mmin -30 predicate matches files modified within the last 30 minutes, and -size +10M selects those larger than 10MB. Combining both in one find invocation over /var returns exactly the files meeting both constraints simultaneously.

Why this answer

The correct command is `find /var -mmin -30 -size +10M`. The `-mmin -30` option tells find to match files modified less than 30 minutes ago (the minus sign means 'less than'), and `-size +10M` matches files larger than 10 megabytes. This combination precisely meets the requirement of files modified within the last 30 minutes and larger than 10MB.

Exam trap

The trap here is confusing `-mmin` (minutes) with `-mtime` (days), and misinterpreting the minus sign: `-mmin -30` means less than 30 minutes ago, while `-mmin 30` means exactly 30 minutes ago. Candidates often mistakenly choose `-mtime -30` thinking it means minutes, or omit the minus sign.

How to eliminate wrong answers

Option A is wrong because `-mmin 30` matches files modified exactly 30 minutes ago, not within the last 30 minutes; it would miss files modified 5 or 20 minutes ago. Option C is wrong because `locate` does not support `-mmin` or `-size` options; locate searches a prebuilt database by filename and cannot filter by modification time or size. Option D is wrong because `-mtime -30` matches files modified within the last 30 days, not 30 minutes, so it would return far too many files.

74
Multi-Selectmedium

A Linux administrator needs to locate all files in the /etc directory that have been modified in the last 24 hours and are not owned by root. Which two commands can be combined to achieve this? (Select TWO.)

Select 2 answers
A.find /etc -mtime 0 -not -user root
B.find /etc -ctime 0 -not -group root
C.find /etc -mmin -1440 -not -user root
D.find /etc -mtime 0 -uid 0
E.find /etc -atime 0 -not -user root
AnswersA, C

-mtime 0 matches files modified within the last 24 hours, and -not -user root excludes root-owned files, meeting both stem constraints in one pass. The -mtime test counts whole 24-hour periods, so 0 covers the current day.

Why this answer

Option A is correct because 'find /etc -mtime 0 -not -user root' searches /etc for files whose modification time falls within the last 24 hours (-mtime 0 means modified less than 1 day ago) and excludes files owned by root via -not -user root. Option C is correct because 'find /etc -mmin -1440 -not -user root' uses -mmin -1440, which matches files modified less than 1440 minutes (24 hours) ago, and likewise filters out root-owned files with -not -user root. Option B is wrong because -ctime checks inode change time, not modification time, and -not -group root filters by group ownership rather than user ownership.

Option D is wrong because -uid 0 selects files owned by root, the opposite of what is required. Option E is wrong because -atime checks access time, not modification time, so it does not identify recently modified files.

Exam trap

The trap is confusing -mtime with -ctime and -atime, and mixing up -user with -group — candidates must remember that -mtime is content modification, -ctime is inode change, and -atime is access.

75
Multi-Selectmedium

A user wants to create a hard link to a file. Which three conditions must be true for a hard link to be created successfully? (Choose three.)

Select 3 answers
A.The source file must have the SUID bit set.
B.The link must have the same name as the source.
C.The source and link must be on the same filesystem.
D.The source file must be a regular file, not a directory.
E.The source file must exist.
AnswersC, D, E

Hard links are directory entries pointing to the same inode, and inode numbers are unique only within a single filesystem. Cross-filesystem linking is therefore impossible, so source and link must reside on the same mounted filesystem.

Why this answer

Option C is correct because a hard link is simply a directory entry that points to the same inode, and inode numbers are only unique within a single filesystem, so the source and the new link must reside on the same filesystem (e.g., both under the same mount point). Option D is correct because hard links to directories are prohibited on Linux/Unix to prevent cycles in the directory tree, so the source must be a regular file (or another non-directory file type). Option E is correct because the link() system call requires an existing source pathname to resolve to an inode; you cannot create a hard link to a file that does not exist.

Option A is not required since the SUID bit is a permission attribute unrelated to link creation, and Option B is wrong because a hard link may have any name and is not required to match the source filename.

Page 1 of 2 · 131 questions totalNext →

Ready to test yourself?

Try a timed practice session using only System Management questions.