Courseiva

CCNA System Management Questions

56 of 131 questions · Page 2/2 · System Management · Answers revealed

76
MCQmedium

A user reports that a specific process is consuming too much CPU. The administrator needs to change the priority of the process to a lower value (nicer). Which command sequence is appropriate?

A.nice -n -10 <PID>
B.kill -15 <PID>
C.chrt --idle <PID>
D.renice +10 -p <PID>
AnswerD

renice adjusts the nice value of an already-running process, and +10 raises it, lowering scheduling priority so the process yields CPU to others. The -p flag targets the given PID, satisfying the requirement to make the busy process nicer.

Why this answer

renice changes the priority of an already running process by PID.

77
MCQmedium

A junior administrator needs to add a persistent mount entry for a new XFS filesystem on /dev/sdb1 at the /data directory so it is mounted automatically at every boot. The administrator opens /etc/fstab and must identify the correct field order for the entry. Which field order should be used in the /etc/fstab line?

A.mount point, device, filesystem type, dump, mount options, fsck pass
B.UUID, filesystem type, mount options, mount point, dump, fsck pass
C.device, mount point, filesystem type, mount options, dump, fsck pass
D.device, filesystem type, mount point, fsck pass, dump, mount options
AnswerC

The fstab file uses six whitespace-separated fields in this exact order: the block device or UUID, the mount point directory, the filesystem type (xfs here), the comma-separated mount options, the dump backup flag, and the fsck pass number. Writing them in this sequence lets systemd's mount units parse and mount /dev/sdb1 at /data on every boot.

Why this answer

The /etc/fstab format is strictly positional: source device, mount point, filesystem type, options, dump flag, and fsck pass. For an XFS volume on /dev/sdb1 mounted at /data, the entry must follow that order so systemd and mount can resolve the device and target correctly and apply options such as defaults or noatime. Misordering any field prevents the persistent mount from working at boot.

Exam trap

The trap here is assuming field order is flexible or that mount options come before the filesystem type, when fstab parsing is strictly positional.

78
MCQeasy

A Linux administrator needs to view the last 10 lines of a log file named 'syslog'. Which command should be used?

A.cat syslog
B.head -10 syslog
C.less syslog
D.tail -10 syslog
AnswerD

`tail -10 syslog` reads from the end of the file and prints exactly the final ten lines, satisfying the requirement to view the last 10 lines of `syslog`. Unlike `head`, which counts from the start, `tail` anchors to the file's end, making it the precise tool for recent log entries.

Why this answer

The 'tail' command outputs the last lines of a file; by default it shows 10 lines.

79
MCQhard

A Linux engineer is troubleshooting a boot issue. The system boots to a command-line interface but does not start the graphical interface. Which systemd target should be set as default to boot into a graphical environment?

A.emergency.target
B.rescue.target
C.graphical.target
D.multi-user.target
AnswerC

Setting the default to graphical.target pulls in multi-user.target plus the display manager and graphical session units, satisfying the stem's requirement to boot into a graphical environment rather than the command-line interface. systemctl set-default graphical.target makes this persistent across reboots, resolving the boot issue.

Why this answer

graphical.target is the systemd target that starts the graphical login manager and desktop environment (it pulls in multi-user.target plus the display manager). Setting it as the default with 'systemctl set-default graphical.target' causes the system to boot into the GUI. The current default can be verified with 'systemctl get-default'.

Exam trap

XK0-006 often tests the mapping between systemd targets and old runlevels — candidates confuse multi-user.target (runlevel 3, CLI) with graphical.target (runlevel 5, GUI) and pick multi-user because it sounds more complete.

How to eliminate wrong answers

Option A is wrong because emergency.target starts only a minimal shell with the root filesystem mounted read-only, used for emergency recovery — no networking or GUI. Option B is wrong because rescue.target starts a single-user rescue shell with local filesystems mounted, used for repair, not a graphical session. Option D is wrong because multi-user.target starts a full multi-user command-line environment with networking but no graphical interface — this is exactly the state the system is currently in, so it would not fix the problem.

80
MCQmedium

A Linux administrator wants to search for all occurrences of the word 'ERROR' in log files under /var/log, ignoring case, and also print the line numbers. Which command should be used?

A.grep -vi 'ERROR' /var/log
B.grep -rin 'ERROR' /var/log
C.grep -rn 'ERROR' /var/log
D.find /var/log -name '*ERROR*'
AnswerB

The -r flag recurses through every file under /var/log, -i matches 'ERROR' case-insensitively, and -n prefixes each match with its line number. Together these satisfy all three requirements: recursive search, case-insensitive matching, and printed line numbers.

Why this answer

The command 'grep -rin ERROR /var/log' combines -r (recursive search through directories), -i (case-insensitive match), and -n (print line numbers). This searches every file under /var/log for 'ERROR' regardless of case and prefixes each match with its line number, exactly matching the requirement.

Exam trap

XK0-006 often tests grep flag combinations — candidates confuse -v (invert) with -i (ignore case) and -c (count) with -n (line number), or forget that -r is required to recurse into /var/log.

How to eliminate wrong answers

Option A is wrong because -v inverts the match (prints non-matching lines) and -i only makes it case-insensitive — it would print every line that does NOT contain ERROR, the opposite of the goal. Option C is wrong because it omits -i, so it would miss lowercase 'error' or mixed-case variants, failing the case-insensitive requirement. Option D is wrong because 'find' locates files by name matching '*ERROR*' rather than searching file contents for the string ERROR, so it does not perform a content search at all.

81
Multi-Selectmedium

A Linux administrator wants to search for the pattern 'ERROR' in all files under /var/log, ignoring case, and display line numbers. Which THREE options should be used with the grep command? (Select THREE).

Select 3 answers
A.-c
B.-i
C.-v
D.-n
E.-r
AnswersB, D, E

The `-i` flag makes grep match case-insensitively, so lines containing 'error', 'Error' or 'ERROR' are all returned. This directly satisfies the stem's requirement to search for the pattern 'ERROR' while ignoring case, rather than matching only uppercase occurrences.

Why this answer

Option B (-i) is correct because it makes grep perform a case-insensitive match, so 'ERROR', 'error', and 'Error' are all found as required. Option D (-n) is correct because it prefixes each matching line with its line number, satisfying the requirement to display line numbers. Option E (-r) is correct because it recursively searches all files under the /var/log directory tree, which is needed to cover 'all files under /var/log'.

Option A (-c) is not appropriate because it only counts matching lines instead of displaying them, and Option C (-v) is wrong because it inverts the match to show non-matching lines rather than the 'ERROR' pattern.

Exam trap

XK0-006 often tests grep flag selection in multi-select questions — candidates include -c or -v because they are common flags, but only -i, -n, and -r match the three stated requirements (case-insensitive, line numbers, recursive).

82
MCQhard

An administrator manages a server with several systemd services. A service named reportgen.service must not start until another service named dbengine.service is fully active, and reportgen should be stopped automatically if dbengine stops. Which directive combination in the reportgen.service unit file achieves this ordering and dependency?

A.After=dbengine.service and Wants=dbengine.service
B.Before=dbengine.service and Wants=dbengine.service
C.Requires=dbengine.service and Before=dbengine.service
D.After=dbengine.service and Requires=dbengine.service
AnswerD

After= establishes ordering so reportgen starts only once dbengine has been activated, and Requires= creates a hard dependency so that if dbengine is stopped or fails, reportgen is also stopped. Together they express both the sequence and the lifecycle coupling the administrator described for these two units.

Why this answer

Ordering and dependency are separate concerns in systemd. After= controls sequence, ensuring reportgen starts once dbengine is active, while Requires= creates a hard dependency so reportgen stops if dbengine stops. Using After= with Requires= satisfies both requirements.

Wants= is too weak to force the stop behavior, and Before= would invert the required startup order.

Exam trap

The trap here is assuming a single directive like Requires handles both ordering and shutdown coupling, when systemd separates ordering from dependency semantics.

83
MCQmedium

An administrator runs the command `ls -l file.txt` and sees the permissions `-rwsr-xr-x`. What special permission is set on this file?

A.SGID
B.Sticky bit
C.No special permission
D.SUID
AnswerD

The `s` in the owner execute position denotes SUID, satisfying the stem's `-rwsr-xr-x` string. When executed, the process runs with the file owner's effective UID rather than the invoking user's, granting elevated privileges. SGID would instead appear in the group execute position, and the sticky bit as `t` on others.

Why this answer

The 's' in the owner execute position indicates the SUID (Set User ID) permission is set.

84
MCQeasy

Which command creates a symbolic link named 'link.txt' that points to 'original.txt'?

A.symlink original.txt link.txt
B.ln -s original.txt link.txt
C.ln original.txt link.txt
D.ln -s link.txt original.txt
AnswerB

The -s flag instructs ln to create a symbolic link rather than a hard link, and argument order matters: the target original.txt precedes the new link name link.txt. This satisfies the requirement for a symlink pointing to original.txt.

Why this answer

ln -s target link_name creates a symbolic link.

85
MCQeasy

A Linux administrator needs to view the kernel ring buffer messages to diagnose a hardware issue. Which command should the administrator use?

A.dmesg
B.cat /var/log/messages
C.tail -f /var/log/syslog
D.journalctl -k
AnswerA

dmesg displays the kernel ring buffer, which contains messages from the kernel, including hardware detection, driver initialization, and errors. This is the primary tool for diagnosing hardware issues at the kernel level. It provides detailed information about devices, interrupts, and other low-level events, making it ideal for the administrator's task.

Why this answer

dmesg is the direct command to view the kernel ring buffer, which contains hardware and driver messages. It is always available and does not depend on system logging services. While journalctl -k can show kernel messages on systemd systems, dmesg is the standard tool for this specific task.

Exam trap

The trap here is assuming that general system logs like /var/log/messages contain all kernel messages; they often do not, especially early boot messages.

86
MCQeasy

A user needs to view the first 15 lines of a large log file. Which command is most appropriate?

A.head -n 15 filename
B.cat filename | head -n 15
C.less -N 15 filename
D.tail -n 15 filename
AnswerA

head outputs the beginning of a file, and -n 15 limits that output to exactly 15 lines, directly satisfying the requirement to view the first 15 lines. tail would show the end, and cat would dump the entire large log.

Why this answer

The command 'head -n 15 filename' is the most appropriate and efficient way to view the first 15 lines of a file. The head command is designed for this purpose, and the -n option specifies the number of lines. This is a standard Linux command and is more direct than piping cat to head.

Exam trap

XK0-006 often tests the difference between head and tail, and the proper syntax for limiting lines; candidates may confuse -n with other options or choose cat | head unnecessarily.

How to eliminate wrong answers

Option B is wrong because while 'cat filename | head -n 15' works, it is less efficient as it invokes two processes and is considered a useless use of cat. Option C is wrong because 'less -N 15 filename' opens the file in a pager with line numbers, but the -N option is for line numbers, not for limiting to 15 lines; less will display the whole file. Option D is wrong because 'tail -n 15 filename' displays the last 15 lines, not the first 15.

87
Multi-Selectmedium

An administrator wants to gather information about disk usage for a specific directory and its subdirectories. Which TWO commands can be used for this purpose? (Choose two.)

Select 2 answers
A.du -sh /path
B.df -h /path
C.ls -lh /path
D.du -h /path
E.stat /path
AnswersA, D

The -s flag collapses output to a single summary total for the directory, while -h renders sizes in human-readable units. Together they report total disk usage for /path and everything beneath it, satisfying the requirement to gather usage across the directory and its subdirectories.

Why this answer

Option A (du -sh /path) is correct because du reports disk usage for the specified directory and, by default, recurses into its subdirectories, while -s summarizes the total into a single figure and -h presents it in human-readable units. Option D (du -h /path) is also correct because du -h /path likewise walks the directory tree and prints the disk usage of the directory and each subdirectory in human-readable form, satisfying the requirement to gather usage information for the directory and its subdirectories. Option B (df -h /path) is not correct because df reports filesystem-level free and used space for the mount point containing the path, not per-directory or per-subdirectory usage.

Option C (ls -lh /path) is not correct because ls only lists file and directory entries with their sizes, without recursively totaling the disk usage of subdirectory contents. Option E (stat /path) is not correct because stat displays metadata such as inode, permissions, and timestamps for a single file or directory, not aggregated disk usage across a directory tree.

Exam trap

XK0-006 often tests the du vs df distinction — candidates pick df because it also reports 'disk usage,' missing that df is filesystem-level and du is directory-level.

88
MCQmedium

A Linux server is configured to use systemd. The administrator wants to ensure that a custom service named 'app.service' starts automatically at boot, even if it has been manually stopped. Which command should be used?

A.systemctl enable app.service
B.systemctl start app.service
C.systemctl preset app.service
D.systemctl reenable app.service
AnswerA

This command creates a symbolic link from the systemd unit file in /etc/systemd/system to the appropriate target's .wants directory, ensuring the service starts at boot. It does not start the service immediately, but it ensures it will be started on subsequent boots. This is the correct way to configure automatic startup.

Why this answer

The correct answer is the command that creates the necessary symbolic links for the service to start automatically at boot. This is done with systemctl enable. The other commands either start the service now, reset enablement, or apply presets, none of which ensure persistent automatic startup.

Exam trap

The trap here is confusing starting a service with enabling it; starting only affects the current session, while enabling configures boot-time activation.

89
Multi-Selectmedium

An administrator needs to update the package cache and upgrade all installed packages on a Debian-based system. Which TWO commands are appropriate for this task? (Select TWO.)

Select 2 answers
A.apt dist-upgrade
B.apt update
C.apt upgrade
D.dpkg --configure -a
E.apt list --upgradable
AnswersB, C

`apt update` refreshes the local package index from the repositories configured in `/etc/apt/sources.list`, so the system knows which upgraded versions are available. It satisfies the stem's "update the package cache" requirement, and must run before any upgrade command such as `apt upgrade` or `apt full-upgrade`.

Why this answer

Option B, `apt update`, is correct because it refreshes the local package index/cache from the repositories configured in /etc/apt/sources.list and sources.list.d, which is the required first step before any upgrade so APT knows the latest available versions. Option C, `apt upgrade`, is correct because it installs the newest versions of all currently installed packages using the refreshed cache, while safely holding back packages that would require removing or adding other packages. Together, `apt update` followed by `apt upgrade` accomplishes updating the package cache and upgrading installed packages on a Debian-based system.

Option A, `apt dist-upgrade`, is not one of the marked answers here; it performs a more aggressive upgrade that can add or remove packages to resolve dependencies, which goes beyond the stated task. Option D, `dpkg --configure -a`, only reconfigures packages left unconfigured after an interrupted installation and does not update the cache or upgrade packages. Option E, `apt list --upgradable`, merely lists packages with available upgrades and performs no cache refresh or installation.

90
MCQmedium

A technician is troubleshooting a service that fails to start at boot. Which systemctl command should be used to ensure the service starts automatically on subsequent boots?

A.systemctl mask service
B.systemctl start service
C.systemctl enable service
D.systemctl reenable service
AnswerC

`systemctl enable` creates the symlinks under the systemd unit's `Wanted` directory, wiring the service into the boot target so systemd starts it automatically on every subsequent boot. It satisfies the stem's requirement for persistent automatic startup, unlike `start`, which only launches the unit for the current session.

Why this answer

systemctl enable creates symlinks so the service starts at boot. The status shown by is-enabled confirms if it is enabled.

91
Multi-Selecthard

A Linux administrator is troubleshooting a systemd service named 'webapp.service' that fails to start. The administrator runs 'systemctl status webapp.service' and sees that the service is in a failed state. Which TWO commands will provide additional diagnostic information about why the service failed? (Choose two.)

Select 2 answers
A.journalctl -u webapp.service
B.journalctl -xe
C.systemctl show webapp.service
D.systemctl cat webapp.service
E.systemctl list-dependencies webapp.service
AnswersA, B

journalctl -u webapp.service displays all journal entries associated with that specific unit, including stdout/stderr from the service and systemd messages about its start attempts. This is a primary tool for diagnosing service failures, as it shows the exact error output and exit codes. It directly addresses the need for additional diagnostic information beyond the basic status output.

Why this answer

To diagnose why a systemd service failed, administrators need access to logs and error messages. journalctl -u webapp.service filters the journal for that unit, showing its output and systemd's messages. journalctl -xe shows recent system-wide errors with explanations, which often include the service failure. Commands like systemctl cat, show, and list-dependencies are for configuration and dependency inspection, not runtime diagnostics.

Exam trap

The trap here is confusing unit configuration inspection commands with log retrieval commands, and assuming that systemctl show or cat will reveal runtime errors when they only display static unit properties or file contents.

92
Multi-Selecthard

A system administrator is working with compressed files. Which THREE commands can be used to view their contents? (Select THREE).

Select 3 answers
A.zgrep
B.cat
C.zcat
D.less
E.zless
AnswersA, C, E

zgrep decompresses the file in memory and searches it for a pattern, printing matching lines to standard output. This lets the administrator view relevant compressed content without extracting the archive first, satisfying the viewing requirement.

Why this answer

Option A, zgrep, is correct because it searches inside gzip-compressed files directly, decompressing the stream on the fly and printing matching lines without requiring manual extraction. Option C, zcat, is correct because it decompresses gzip files to standard output, allowing their contents to be viewed (often piped to a pager). Option E, zless, is correct because it is a pager wrapper that decompresses gzip files and displays them page by page, making it ideal for viewing compressed content interactively.

Options B (cat) and D (less) are not marked correct because they operate on plain uncompressed files and would output raw binary garbage when applied directly to a gzip-compressed file.

Exam trap

The trap here is assuming that standard text utilities like cat and less automatically handle gzip-compressed files; the exam expects you to know the z-prefixed variants are required for transparent decompression.

93
MCQhard

Given an ACL entry 'u:john:rwx' on a file, which command would remove only the ACL entry for user john without affecting other ACL entries?

A.setfacl -k /path/to/file
B.setfacl -m u:john:- /path/to/file
C.setfacl -x u:john /path/to/file
D.setfacl -b /path/to/file
AnswerC

setfacl -x removes the specified ACL entry only, leaving other entries intact. Targeting u:john deletes just john's entry, satisfying the requirement to remove that single entry without disturbing the remaining access ACL or default ACL entries on the file.

Why this answer

The setfacl -x u:john /path/to/file command removes only the ACL entry for user john while leaving all other ACL entries (group entries, mask, other users) intact. The -x flag specifically deletes the named entry, which is exactly what the question requires. This is the surgical removal operation in the setfacl toolkit.

Exam trap

XK0-006 often tests the distinction between modifying an ACL entry to zero permissions (-m u:user:-) and actually deleting the entry (-x u:user) — candidates pick -m because it looks like it removes access, but the entry remains.

How to eliminate wrong answers

Option A is wrong because setfacl -k removes the default ACL entries on a directory, not a specific named user entry, and it does not target john. Option B is wrong because setfacl -m u:john:- modifies john's entry to have no permissions but leaves the entry present in the ACL, so the entry still exists rather than being removed. Option D is wrong because setfacl -b removes ALL extended ACL entries, wiping out every user and group entry, not just john's.

94
MCQeasy

A Linux administrator needs to change the permissions of a file to be readable and writable by the owner, readable by the group, and no access for others. Which command accomplishes this?

A.chmod 600 file
B.chmod 664 file
C.chmod 644 file
D.chmod 640 file
AnswerD

chmod 640 sets owner read and write (6), group read only (4), and no permissions for others (0). The octal digits map directly onto the required owner, group and other access, satisfying the stated permission set.

Why this answer

chmod 640 sets owner read+write (6), group read (4), and others no access (0), which matches the requirement exactly. The octal notation maps 4=read, 2=write, 1=execute, so 6=rw, 4=r, 0=none. This is the standard permission set for files that should be private to the owner but readable by a trusted group.

Exam trap

XK0-006 often tests octal-to-symbolic conversion under time pressure — candidates misread 'readable by group' as 'readable by others' and pick 644, or forget the group entirely and pick 600.

How to eliminate wrong answers

Option A is wrong because chmod 600 gives the group no permissions at all, but the requirement states the group must have read access. Option B is wrong because chmod 664 grants others read access (the last 4), violating the 'no access for others' requirement. Option C is wrong because chmod 644 also grants others read access, which the requirement explicitly forbids.

95
MCQhard

A Linux administrator is troubleshooting a system that fails to mount the root filesystem during boot, dropping to an emergency shell. The administrator suspects that a recently added entry in /etc/fstab is incorrect. Which of the following commands should be used to verify the syntax and mountability of all entries in /etc/fstab without actually mounting them?

A.fsck -A
B.findmnt --verify
C.mount -a
D.blkid
AnswerB

The findmnt --verify command checks the syntax of /etc/fstab and other mount configuration files, and verifies that the entries are valid and can be mounted, without actually mounting them. It reports errors and warnings, making it ideal for troubleshooting a suspected incorrect fstab entry that prevents boot.

Why this answer

The findmnt --verify command is designed to validate the syntax and mountability of entries in /etc/fstab and related files without mounting them. It checks for common errors such as invalid device names, duplicate mount points, and unsupported options. This allows the administrator to identify problematic entries before attempting a reboot, avoiding a boot failure.

Other commands either mount the filesystems or perform unrelated checks.

Exam trap

The trap here is confusing mount -a with a verification tool; mount -a actually mounts filesystems and can cause the same failure, while findmnt --verify safely checks without mounting.

96
Multi-Selecteasy

Which of the following commands can be used to display the contents of a file one page at a time? (Choose two.)

Select 2 answers
A.less
B.head
C.cat
D.tail
E.more
AnswersA, E

`less` reads the file lazily and renders it in a scrollable pager, displaying one screenful at a time while allowing forward and backward navigation without loading the whole file into memory. This directly satisfies the requirement to view file contents page by page, unlike `cat`, which dumps everything at once.

Why this answer

Option A, less, is correct because it is a pager that displays a file's contents one screen (page) at a time, allowing forward and backward navigation with keys like Space, b, and q. Option E, more, is also correct because it is a pager that shows file contents one page at a time, advancing with Space and exiting with q, though it traditionally only scrolls forward. Option B, head, is incorrect because it prints only the first 10 lines (by default) and exits, not paging through the file.

Option C, cat, is incorrect because it concatenates and dumps the entire file to standard output at once without pagination. Option D, tail, is incorrect because it prints only the last 10 lines (by default) and exits, not displaying the file page by page.

Exam trap

The trap here is that candidates may confuse `cat` as a pagination tool because it displays file contents, but it lacks any paging or interactive control, while `head` and `tail` are often mistakenly thought to paginate because they show a subset of lines.

97
MCQmedium

A system administrator wants to ensure that a service starts automatically at boot time using systemd. Which command should be used?

A.systemctl start service
B.systemctl daemon-reload
C.systemctl reenable service
D.systemctl enable service
AnswerD

`systemctl enable service` creates the symbolic links in the systemd unit directories that cause the service to be pulled into the boot transaction, satisfying the requirement that it start automatically at boot. It does not start the unit immediately, unlike `systemctl start`, which affects only the current session.

Why this answer

systemctl enable service creates the necessary symlinks so the service's unit is pulled into the appropriate systemd target at boot, ensuring it starts automatically. This is the standard systemd command for enabling a service at boot time. It does not start the service immediately, but it guarantees it will start on the next boot.

Exam trap

XK0-006 often tests the difference between start (runtime) and enable (boot-time persistence) — candidates pick 'start' because the question mentions 'starts automatically,' conflating immediate start with boot-time enablement.

How to eliminate wrong answers

Option A is wrong because systemctl start service starts the service immediately in the current session but does not configure it to start at boot. Option B is wrong because systemctl daemon-reload reloads unit files after changes but does not enable any service. Option C is wrong because systemctl reenable service is not a valid systemd subcommand — the correct form would be disable followed by enable, or just enable to refresh symlinks.

98
MCQmedium

A user wants to run a command that will continue running even after the user logs out. Which command should be used?

A.disown command
B.command &
C.bg command
D.nohup command &
AnswerD

nohup makes the process immune to SIGHUP, so it survives the terminal hangup when the user logs out; the trailing & backgrounds it so control returns immediately. Together they satisfy the requirement that the command keep running after logout.

Why this answer

nohup makes the command immune to hangups and runs in the background.

99
Multi-Selectmedium

A system administrator wants to display a list of all currently running processes, including those of other users, with full command lines. Which TWO commands can achieve this? (Select TWO.)

Select 2 answers
A.pstree
B.top
C.ps aux
D.htop
E.ps -ef
AnswersC, E

`ps aux` lists every process on the system, not just the invoking user's, satisfying the requirement to include other users' processes. The `a` flag selects processes from all terminals, `u` adds user-oriented detail, and `x` includes processes without a controlling terminal, while the command column shows full command lines.

Why this answer

Both ps aux (C) and ps -ef (E) are correct because the ps command with these option sets lists every process on the system, not just the current user's, and includes the full command line for each process. ps aux uses BSD-style syntax where 'a' shows processes from all users, 'u' displays user-oriented format, and 'x' includes processes without a controlling terminal, with the COMMAND column showing the full command line. ps -ef uses UNIX-style syntax where '-e' selects all processes and '-f' produces full-format output including UID, PID, PPID, and the complete command line. pstree (A) only shows processes as a hierarchical tree and does not display full command lines with arguments. top (B) and htop (D) are interactive process viewers that by default show only a truncated command column and are not the standard non-interactive way to list all processes with full command lines.

Exam trap

XK0-006 often tests the distinction between interactive monitors (top, htop) and static listing commands (ps) — candidates pick top or htop because they 'show all processes,' but the question requires a command that outputs a full listing with full command lines.

100
MCQmedium

An administrator needs to view the last 20 lines of the systemd journal for the 'sshd' service. Which command should be used?

A.systemctl status sshd | tail -20
B.journalctl -u sshd -n 20
C.journalctl -u sshd --since '1 hour ago'
D.journalctl -u sshd -f
AnswerB

The -u flag filters journal entries to the sshd unit, while -n 20 limits output to the most recent 20 lines. Together they satisfy the requirement to view the last 20 journal lines for that specific service.

Why this answer

The command `journalctl -u sshd -n 20` directly queries the systemd journal for entries related to the sshd unit (`-u sshd`) and displays the last 20 lines (`-n 20`). This is the correct and efficient way to view recent journal entries for a specific service. It leverages journalctl's native filtering and tailing capabilities without piping or additional processing.

Exam trap

The trap here is confusing `systemctl status` with `journalctl` for viewing logs, or misinterpreting `-f` as a way to show recent lines rather than follow the log in real-time.

How to eliminate wrong answers

Option A is wrong because `systemctl status sshd` shows the service status summary, not the journal logs, and piping to `tail -20` would only show the last 20 lines of that status output, not the actual journal entries. Option C is wrong because `--since '1 hour ago'` filters by time, not by line count, and would display all entries from the last hour, which may be more or fewer than 20 lines. Option D is wrong because `-f` follows the journal in real-time, displaying new entries as they arrive, rather than showing the last 20 lines and exiting.

101
MCQhard

A system administrator runs the command 'chmod 4755 /usr/local/bin/backup'. What effect does this have on the file?

A.Sets the sticky bit and gives rwxr-xr-x permissions
B.Sets the SUID bit and gives rwxr-xr-x permissions
C.Sets the SGID bit and gives rwxr-xr-x permissions
D.Sets the SUID bit and gives rwxrwxr-x permissions
AnswerB

The leading 4 sets the SUID bit, so the program runs with the file owner's privileges rather than the invoking user's. The remaining 755 grants rwx to the owner and r-x to group and others, matching the octal digits exactly. This satisfies the stem's requirement to interpret chmod 4755 correctly.

Why this answer

The 4 in the first digit sets the SUID bit, so the file runs with the owner's permissions. 755 sets rwxr-xr-x.

102
MCQmedium

A developer wants to change all occurrences of 'foo' to 'bar' in a configuration file and save the changes in-place. Which sed command should be used?

A.sed -i 's/foo/bar/' file
B.sed -n 's/foo/bar/p' file
C.sed 's/foo/bar/g' file
D.sed -i 's/foo/bar/g' file
AnswerD

The -i flag edits the file in place, while the g suffix replaces every occurrence of foo with bar on each line rather than only the first. This satisfies the requirement to change all matches and save changes directly to the configuration file.

Why this answer

The correct command is sed -i 's/foo/bar/g' file because it combines in-place editing (-i) with the global substitution flag (g), replacing every occurrence of 'foo' on each line. Without -i, changes are only printed to stdout; without g, only the first match per line is replaced.

Exam trap

XK0-006 often tests the combination of -i and g flags — candidates forget that -i alone does not make substitution global, and g alone does not modify the file.

How to eliminate wrong answers

Option A is wrong because it lacks the g flag, so only the first occurrence of 'foo' per line is replaced, not all occurrences. Option B is wrong because -n suppresses automatic printing and the p flag only prints substituted lines, and it does not modify the file in place. Option C is wrong because it lacks -i, so the file is not modified; the result is only written to standard output.

103
Multi-Selectmedium

A Linux administrator needs to add an ACL entry to grant read permission to a user named 'jdoe' on a file. Which TWO commands can be used to achieve this? (Select TWO).

Select 2 answers
A.setfacl -m u:jdoe:r file
B.setfacl --modify u:jdoe:r file
C.chown jdoe file
D.setfacl -x u:jdoe file
E.chmod u+r file
AnswersA, B

setfacl -m invokes modify mode, and the entry u:jdoe:r adds an ACL granting user jdoe read permission on the file without altering the existing owner, group or other bits. This directly satisfies the requirement to add a read ACL entry for that named user.

Why this answer

Option A, `setfacl -m u:jdoe:r file`, is correct because `-m` is the short form of `--modify`, and `u:jdoe:r` adds or modifies an ACL entry granting user jdoe read permission on the file. Option B, `setfacl --modify u:jdoe:r file`, is correct because it is the long-form equivalent of the same command, performing the identical ACL modification. Option C, `chown jdoe file`, only changes the file's owner and does not create an ACL entry, so it does not grant read permission via ACL.

Option D, `setfacl -x u:jdoe file`, removes an existing ACL entry for jdoe rather than adding one. Option E, `chmod u+r file`, modifies the standard Unix permission bits for the file's owner, not an ACL entry for jdoe.

Exam trap

The trap is confusing ACL modification with ownership change (chown) or standard permission change (chmod), and failing to recognize that -m and --modify are equivalent long/short options for setfacl.

104
MCQeasy

Which directory in the Linux filesystem contains essential user command binaries that are needed for booting and repairing the system?

A./usr/bin
B./bin
C./sbin
D./opt
AnswerB

/bin holds essential user command binaries required for booting and single-user repair, such as ls, cp and sh. It is distinct from /sbin, which holds system administration binaries, and /usr/bin, which holds non-essential user commands.

Why this answer

/bin contains essential command binaries required for booting and recovery.

105
MCQmedium

An administrator notices that a service named 'httpd' is not running. They want to check its current status and, if inactive, start it. Which set of systemctl commands should be used?

A.systemctl list-units httpd; if inactive, systemctl run httpd
B.systemctl show httpd; if inactive, systemctl launch httpd
C.systemctl is-active httpd; if inactive, systemctl enable httpd
D.systemctl status httpd; if inactive, systemctl start httpd
AnswerD

systemctl status httpd reports whether the unit is active, inactive or failed, and systemctl start httpd launches it if inactive. This pairing satisfies the requirement to check current state before conditionally starting the service, using systemd's native unit management.

Why this answer

systemctl status httpd shows the status; if inactive, systemctl start httpd starts it. The other options have incorrect commands or syntax.

106
MCQhard

A Linux administrator is troubleshooting a server that fails to mount a filesystem listed in /etc/fstab during boot, causing the system to drop into emergency mode. The administrator wants to prevent the system from entering emergency mode if this particular mount fails, while still attempting to mount it. Which fstab option should be added to the mount entry?

A.nouser
B.auto
C.nofail
D.defaults
AnswerC

The nofail option tells systemd that the mount is not required for boot. If the device is missing or the mount fails, the boot process continues without entering emergency mode. This directly addresses the requirement to avoid emergency mode while still attempting the mount.

Why this answer

The nofail option in /etc/fstab instructs systemd to ignore mount failures for that entry, allowing the boot to proceed even if the device is unavailable. This prevents the system from dropping into emergency mode. The other options either do not affect error handling or are already implied by defaults, so they do not provide the needed resilience.

Exam trap

The trap here is confusing nofail with other mount options like auto or defaults, which do not prevent emergency mode on mount failure.

107
MCQmedium

An administrator wants to find all files in the current directory tree that are larger than 100 MB and have the .log extension. Which find command will accomplish this?

A.find . -name '*.log' -size +100M
B.find . -name '*.log' -size +100MB
C.find . -name '*.log' -size -100M
D.find . -type f -size +100M
AnswerA

The `-size +100M` predicate filters on file size in mebibytes, while `-name '*.log'` matches the extension, and the starting point `.` recurses the current directory tree. Both constraints from the stem are satisfied in a single pass, with no piping required.

Why this answer

Find . -name '*.log' -size +100M. This command searches recursively from the current directory (.) for files with names matching '*.log' (-name '*.log') and with size greater than 100 MB (-size +100M). Option B is incorrect because the size syntax +100MB is wrong; the correct suffix is M for megabytes.

Option C uses -size -100M which finds files smaller than 100 MB. Option D uses -type f (files only) but does not filter by .log extension, so it would include all files larger than 100 MB regardless of extension.

108
MCQeasy

Which command is used to display the contents of a compressed log file without decompressing it?

A.head
B.zcat
C.cat
D.less
AnswerB

`zcat` streams decompressed data from gzip-compressed files straight to standard output, leaving the original archive untouched on disk. This satisfies the stem's constraint of reading a compressed log's contents without decompressing it, since no extracted file is written. It also handles `.gz` logs directly, unlike `cat`, which would emit raw binary.

Why this answer

zcat (equivalent to gzip -dc) reads a gzip-compressed file and writes the decompressed content to standard output without modifying the original file. It is the standard tool for viewing .gz log files in place, and it can be piped to less or grep for further processing.

Exam trap

XK0-006 often tests whether candidates know that cat and head do not decompress — the trap is assuming any file-reading command handles gzip transparently.

How to eliminate wrong answers

Option A is wrong because head reads the first lines of a file as-is; on a gzip file it would output binary garbage, not decompressed text. Option C is wrong because cat concatenates and prints raw file bytes — again producing binary output on a compressed file. Option D is wrong because less, while it can display text, does not decompress gzip files by default (though less can be configured with LESSOPEN to pipe through gzip, that is not its native behavior).

109
Multi-Selecteasy

A user wants to view the contents of a text file one page at a time. Which two commands can be used? (Choose two.)

Select 2 answers
A.less
B.cat
C.tail
D.head
E.more
AnswersA, E

less displays file contents one screenful at a time, supporting forward and backward scrolling plus in-page searching. It satisfies the paging requirement directly, unlike cat, which dumps the entire file to standard output without pagination.

Why this answer

Both less (A) and more (E) are paging utilities that display a text file one screenful at a time and pause for the user to scroll, which directly matches the requirement. less is the more capable pager, supporting both forward and backward navigation plus searching, while more provides basic forward paging and is available on virtually all Unix-like systems. The other commands do not page output: cat (B) dumps the entire file to standard output at once, and tail (C) and head (D) only print the last or first lines (10 by default) respectively, so none of them let the user view the file page by page.

110
MCQeasy

Which directory in the Filesystem Hierarchy Standard (FHS) contains essential user commands available to all users, such as 'ls' and 'cp'?

A./sbin
B./opt
C./bin
D./usr/bin
AnswerC

/bin holds essential user binaries such as ls and cp, required for single-user mode and all users. The FHS reserves /sbin for system administration binaries and /usr/bin for non-essential user commands, so /bin uniquely satisfies the stem's requirement for essential commands available to everyone.

Why this answer

The /bin directory in the FHS contains essential user commands that must be available in single-user mode and for all users, such as ls, cp, mv, and cat. These binaries are required for basic system operation and are on the root filesystem so they are available even when other filesystems are not mounted. This matches the question's description precisely.

Exam trap

XK0-006 often tests the FHS distinction between /bin and /usr/bin, and candidates pick /usr/bin because it contains the same commands, forgetting that /bin is specifically for essential commands available during early boot and single-user mode.

How to eliminate wrong answers

Option A is wrong because /sbin contains essential system binaries intended for system administration and root use, such as fdisk, mkfs, and reboot — not general user commands like ls and cp. Option B is wrong because /opt is reserved for optional add-on application software packages, not core user commands. Option D is wrong because /usr/bin contains most user commands, but these are not considered essential for single-user mode or early boot; the FHS distinguishes /bin (essential, root filesystem) from /usr/bin (non-essential, may be on a separate filesystem).

111
MCQhard

An administrator wants to change the default systemd target to multi-user.target so the system boots to a text console. Which command should be used?

A.systemctl isolate multi-user.target
B.systemctl set-default multi-user.target
C.systemctl enable multi-user.target
D.systemctl mask multi-user.target
AnswerB

systemctl set-default multi-user.target writes the default target symlink, so systemd boots to a text console on subsequent starts. This directly satisfies the requirement to change the default boot target persistently, unlike isolate, which only affects the running session.

Why this answer

systemctl set-default multi-user.target sets the default target. systemctl isolate changes the current target but not the default. enable and mask are for services, not targets.

112
MCQhard

An administrator is troubleshooting a boot issue. The system boots to a console with limited functionality. Which systemd target should be used to bring up the system with network and multi-user support?

A.emergency.target
B.graphical.target
C.rescue.target
D.multi-user.target
AnswerD

The multi-user.target starts systemd's non-graphical multi-user mode, activating networking and allowing multiple concurrent logins without a display manager. It satisfies the stem's requirement for network and multi-user support from a limited console, unlike graphical.target, which additionally requires a graphical session.

Why this answer

multi-user.target provides a non-graphical multi-user system with network.

113
Multi-Selectmedium

An administrator needs to grant read and write access to the 'developers' group on a directory while preserving existing permissions for the owner and others. Which TWO commands can be used to modify ACLs? (Choose two.)

Select 1 answer
A.chmod g+rw /dir
B.getfacl /dir
C.setfacl -m u:developers:rw /dir
D.setfacl -x g:developers /dir
E.setfacl -m g:developers:rw /dir
AnswersE

setfacl -m g:developers:rw sets an ACL entry for the 'developers' group, granting read and write access. This directly fulfills the requirement and is correct.

Why this answer

setfacl -m g:developers:rw /dir is the correct command to grant read-write access to the developers group. Option C uses u:developers, which sets an ACL for a user named 'developers', not the developers group, so it does not satisfy the requirement. chmod changes standard permissions, getfacl only displays ACLs, and setfacl -x removes ACL entries. Therefore, only option E is correct.

Exam trap

Candidates often confuse the user and group flags in setfacl. The -m option can specify either u: for user or g: for group. Ensure the correct entity type is used based on whether you need to assign permissions to a user or a group.

114
MCQmedium

A Linux administrator is configuring a persistent mount for a new 2TB XFS filesystem on /dev/sdb1 so it mounts automatically at /data with quota accounting enabled. The administrator edits /etc/fstab and adds the entry, then runs mount -a to validate it. Which fstab field combination correctly applies user and group quota accounting on this XFS mount?

A./dev/sdb1 /data xfs defaults,quota 0 0
B./dev/sdb1 /data xfs defaults,uquota,gquota 0 0
C./dev/sdb1 /data xfs defaults,noquota 0 0
D./dev/sdb1 /data xfs defaults,usrquota,grpquota 0 0
AnswerB

The XFS driver recognizes uquota and gquota as the correct mount options to activate user and group quota accounting. Placing them in the fourth fstab field ensures the filesystem mounts with quota accounting enabled at boot. After mounting, the administrator still must run xfs_quota to assign limits, but accounting itself is correctly enabled by these options combined with defaults.

Why this answer

XFS uses its own quota mount keywords rather than the legacy ext-family usrquota/grpquota options. Specifying uquota and gquota in the fourth fstab field enables both user and group quota accounting each time the filesystem mounts, which satisfies the requirement for automatic quota enforcement at boot. The remaining options either use unsupported keywords or disable quotas entirely.

Exam trap

The trap here is assuming XFS accepts the same usrquota and grpquota keywords that ext4 uses, when XFS actually requires its own uquota and gquota mount options.

115
MCQhard

A technician needs to create a new ext4 filesystem on /dev/sdb1 and mount it persistently at /mnt/data. Which set of commands accomplishes this?

A.mkfs -t ext4 /dev/sdb1; mount /dev/sdb1 /mnt/data; echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab
B.mkfs.ext4 /dev/sdb1; echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab
C.mkfs.ext4 /dev/sdb1; mount /dev/sdb1 /mnt/data
D.echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab; mount -a
E.fdisk /dev/sdb1; mount /dev/sdb1 /mnt/data; echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab
AnswerA

mkfs -t ext4 creates the filesystem, mount attaches it at /mnt/data, and the /etc/fstab entry with dump 0 and pass 2 makes the mount persistent across reboots. The pass value 2 suits a non-root filesystem.

Why this answer

The correct sequence must (1) create the filesystem with mkfs, (2) mount it now so it is usable immediately, and (3) add an /etc/fstab entry so the mount persists across reboots. Option A does all three in the right order using mkfs -t ext4, mount, and an fstab line with dump=0 and fsck pass=2. The fsck pass value of 2 is appropriate for a non-root filesystem.

Exam trap

The trap here is conflating 'persistent' with 'immediately usable' — candidates forget that fstab alone does not mount the filesystem, and that mkfs must precede any mount attempt.

How to eliminate wrong answers

Option B is wrong because it creates the filesystem and writes fstab but never mounts the filesystem, so /mnt/data is not active until reboot or a manual mount -a. Option C is wrong because it mounts the filesystem but omits the /etc/fstab entry, so the mount is not persistent. Option D is wrong because it writes fstab and runs mount -a but never creates the ext4 filesystem, so mount -a would fail or mount an unrecognized filesystem.

Option E is wrong because fdisk is a partitioning tool, not a filesystem creation tool; running fdisk on /dev/sdb1 would attempt to partition a partition and does not create ext4.

116
Multi-Selecteasy

An administrator needs to create a hard link to an existing file. Which two statements are true about hard links? (Choose two.)

Select 2 answers
A.Hard links can be created for directories
B.Hard links can be created across different filesystems
C.Hard links are indistinguishable from the original file
D.Hard links share the same inode number
E.Deleting the original file removes the hard link
AnswersC, D

Hard links share the same inode as the original file, so both directory entries reference identical metadata and data blocks. No separate inode exists to distinguish them, satisfying the stem's requirement that the link is indistinguishable from the original. Deleting either name leaves the other fully functional until the link count reaches zero.

Why this answer

Option C is correct because a hard link is simply another directory entry that points to the same inode, so it has identical permissions, ownership, timestamps, and content as the original file and cannot be distinguished from it by normal file operations. Option D is correct because creating a hard link with ln (without -s) increments the inode's link count and gives the new name the same inode number as the original file, which is why both names reference the same data blocks. Option A is wrong because hard links to directories are prohibited on Linux filesystems to prevent cycles in the directory tree.

Option B is wrong because a hard link must reside on the same filesystem as the target file, since inode numbers are only unique within a single filesystem. Option E is wrong because deleting the original name only decrements the link count; the data remains accessible through the remaining hard link until the link count reaches zero.

117
MCQeasy

An administrator wants to find all files larger than 100MB in the /var directory. Which command should be used?

A.find /var -size +100kb
B.find /var -type f -size +100M
C.ls -l /var | grep 100M
D.du -sh /var/* | grep M
AnswerB

The -size +100M predicate matches regular files exceeding 100 mebibytes, and -type f restricts results to files rather than directories. This satisfies the stem's requirement to locate files larger than 100MB within /var using a single find invocation.

Why this answer

The find command with -size +100M searches for files larger than 100 megabytes, and -type f restricts results to regular files. Running 'find /var -type f -size +100M' correctly locates all regular files under /var exceeding 100MB. This is the standard, precise way to search by size in Linux.

Exam trap

XK0-006 often tests whether candidates confuse size units (kb vs M vs G) and forget that find requires -type f to exclude directories, leading them to pick options that match the wrong unit or miss subdirectories.

How to eliminate wrong answers

Option A is wrong because '+100kb' searches for files larger than 100 kilobytes, not 100 megabytes, and it omits -type f so it may match directories. Option C is wrong because 'ls -l /var | grep 100M' only lists the immediate contents of /var and greps for the literal string '100M', which does not reliably match file sizes and misses subdirectories. Option D is wrong because 'du -sh /var/*' shows the total size of each top-level item in /var, not individual files larger than 100MB, and grep 'M' matches any size containing 'M'.

118
MCQmedium

A process is consuming excessive CPU and needs to be terminated immediately. The PID is 1234. Which command will terminate the process with the most forceful signal?

A.kill -15 1234
B.kill -1 1234
C.kill -9 1234
D.kill -19 1234
AnswerC

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 1234 immediately without allowing cleanup — satisfying the stem's demand for the most forceful signal. Weaker signals such as SIGTERM (15) can be trapped or deferred, which would not guarantee immediate termination.

Why this answer

kill -9 (SIGKILL) forcibly terminates the process. SIGTERM (15) is graceful; SIGHUP (1) reloads config; SIGSTOP (19) suspends.

119
Multi-Selectmedium

A system administrator needs to monitor real-time process information and system resource usage. Which two commands can be used for this purpose? (Choose two.)

Select 2 answers
A.kill
B.top
C.htop
D.jobs
E.ps aux
AnswersB, C

top reads /proc to display live per-process CPU, memory and load statistics, refreshing periodically. It satisfies the real-time process and resource monitoring requirement, complementing htop, which offers the same underlying data with an enhanced interactive interface.

Why this answer

Option B (top) is correct because it launches an interactive, real-time process viewer that continuously refreshes CPU, memory, load average, and per-process statistics, exactly matching the requirement for live process and resource monitoring. Option C (htop) is also correct because it is an enhanced interactive process viewer that provides the same real-time monitoring with additional features such as colorized output, scrollable process lists, and per-core CPU meters. Option A (kill) is incorrect because it only sends signals to terminate or control existing processes and does not display monitoring data.

Option D (jobs) is incorrect because it merely lists jobs in the current shell session and shows no system resource usage. Option E (ps aux) is incorrect because it produces a static snapshot of processes at the moment of execution rather than continuous real-time monitoring.

Exam trap

The trap here is confusing static process-listing tools like ps and jobs with true real-time monitoring tools; candidates who see 'process information' and reflexively pick ps aux miss the 'real-time' qualifier that only top and htop satisfy.

120
MCQeasy

Which command is used to display the current process hierarchy in a tree format?

A.pstree
B.lsproc
C.ps aux
D.top
AnswerA

pstree reads the process table and renders parent-child relationships as an indented tree, showing the hierarchy from init or the specified PID downwards. This directly satisfies the requirement to display the current process hierarchy in tree format.

Why this answer

The pstree command displays running processes as a tree, showing parent-child relationships with branches, which is exactly what the question asks for. It reads process information from /proc and renders the hierarchy visually, optionally with -p to show PIDs and -u to show users. None of the other commands present the hierarchy in tree format.

Exam trap

The trap is confusing 'list all processes' (ps aux, top) with 'show process hierarchy as a tree' — candidates who skim the question pick ps aux because it is the most familiar process-listing command.

How to eliminate wrong answers

Option B is wrong because lsproc is not a standard Linux command — there is no such utility in coreutils or procps, so it cannot display a process tree. Option C is wrong because ps aux lists all processes in a flat, tabular format with columns for user, PID, CPU, memory, and command, but it does not show parent-child relationships as a tree. Option D is wrong because top provides a real-time, dynamically refreshing view of processes sorted by resource usage, again in a flat list rather than a hierarchical tree.

121
MCQmedium

Which command will display the disk usage of each directory in the current directory, in human-readable format?

A.du -h
B.fdisk -l
C.ls -lh
D.df -h
AnswerA

du reports disk usage per directory, and the -h flag converts block counts into human-readable units such as KB, MB and GB. Running it in the current directory lists each subdirectory's consumption, matching the requirement for readable per-directory usage figures.

Why this answer

The `du -h` command displays disk usage for each directory in the current directory, with the `-h` flag converting sizes into human-readable formats (e.g., K, M, G). This is the correct tool for per-directory disk usage reporting.

Exam trap

The trap here is that candidates confuse `df -h` (filesystem-level usage) with `du -h` (directory-level usage), often picking `df -h` because it also shows human-readable output.

How to eliminate wrong answers

Option B is wrong because `fdisk -l` lists partition tables on block devices, not directory-level disk usage. Option C is wrong because `ls -lh` lists file and directory names with sizes, but it does not compute recursive disk usage for directories. Option D is wrong because `df -h` shows filesystem-level free and used space, not per-directory usage.

122
MCQeasy

Which command displays the disk usage of files and directories in a human-readable format (e.g., KB, MB)?

A.df -h
B.ls -lh
C.stat -h
D.du -h
AnswerD

The `du -h` command satisfies the human-readable requirement by appending the `-h` flag, which converts raw byte counts into scaled units such as KB, MB and GB. Unlike `df`, which reports filesystem-level capacity, `du` measures actual disk usage of files and directories, matching the stem precisely.

Why this answer

The `du -h` command (disk usage with human-readable flag) recursively summarizes disk usage for files and directories, appending size suffixes like K, M, G for kilobytes, megabytes, and gigabytes. This directly matches the question's requirement to display disk usage in a human-readable format.

Exam trap

The trap here is that candidates confuse `df -h` (filesystem-level free space) with `du -h` (per-file/directory disk usage), or assume `ls -lh` shows disk usage when it actually shows logical file size, not the blocks consumed on disk.

How to eliminate wrong answers

Option A is wrong because `df -h` reports filesystem-level disk space usage (free/used blocks on mounted partitions), not the disk usage of individual files and directories. Option B is wrong because `ls -lh` lists file sizes in human-readable format but does not compute or display disk usage (the actual blocks consumed on disk), which can differ from file size due to sparse files or block allocation. Option C is wrong because `stat -h` is not a valid Linux command; `stat` uses `-c` or `--format` for custom output and does not have a `-h` flag for human-readable sizes.

123
MCQhard

An administrator needs to apply a set of permissions to an existing directory and all its contents, setting the owner to 'rwx', group to 'rx', and others to '---'. Additionally, newly created files within the directory should inherit the group. Which commands should the administrator run? (Assume the directory is /data, and the group is 'staff'.)

A.chmod -R 750 /data; chmod g+s /data
B.chmod 750 /data; chmod g+s /data
C.chmod -R 755 /data; chmod g+s /data
D.chmod -R 750 /data
AnswerA

The recursive 750 sets owner rwx, group rx and no others permissions across /data and its contents, while the setgid bit forces new files to inherit the staff group rather than the creator's primary group, meeting the inheritance constraint.

Why this answer

The command 'chmod -R 750 /data' recursively sets permissions for the directory and all its contents to owner rwx, group rx, and others none. The command 'chmod g+s /data' sets the setgid bit on the directory, ensuring that newly created files and subdirectories inherit the group ownership of the directory (staff). Together, these commands meet the requirements.

Exam trap

XK0-006 often tests the difference between recursive and non-recursive chmod, and the effect of the setgid bit on directories, leading candidates to forget the -R flag or the setgid command.

How to eliminate wrong answers

Option B is wrong because 'chmod 750 /data' without the -R flag only changes the permissions of the directory itself, not its contents. Option C is wrong because 'chmod -R 755 /data' sets others to r-x, which violates the requirement of others having no permissions (---). Option D is wrong because it lacks the 'chmod g+s /data' command, so newly created files will not inherit the group.

124
MCQmedium

A user wants to create a symbolic link to a file named 'original' in their home directory. Which command creates a symbolic link named 'link'?

A.ln original link
B.ln -s original link
C.ln -s link original
D.symlink original link
AnswerB

ln -s creates a symbolic link, with the target 'original' first and the new link name 'link' second. The -s flag distinguishes it from a hard link, satisfying the requirement for a symlink in the home directory.

Why this answer

The 'ln -s' command creates a symbolic (soft) link. The syntax is 'ln -s <target> <linkname>', so 'ln -s original link' creates a symlink named 'link' that points to 'original'. Without the -s flag, ln creates a hard link instead.

Exam trap

XK0-006 often tests the argument order of 'ln -s' and the hard-link versus symbolic-link distinction, causing candidates to reverse the target and link name or forget the -s flag.

How to eliminate wrong answers

Option A is wrong because 'ln original link' creates a hard link, not a symbolic link — hard links share the same inode and cannot span filesystems or point to directories. Option C is wrong because the arguments are reversed: 'ln -s link original' would create a symlink named 'original' pointing to 'link', which is the opposite of what was requested. Option D is wrong because 'symlink' is not a standard Linux command; the correct utility is 'ln' with the -s option.

125
MCQmedium

A Linux administrator needs to create a new user account 'jdoe' with a home directory /home/jdoe and the default shell /bin/bash. Which command will accomplish this?

A.groupadd -m -s /bin/bash jdoe
B.adduser jdoe --home /home/jdoe --shell /bin/bash
C.useradd -m -s /bin/bash jdoe
D.usermod -d /home/jdoe -s /bin/bash jdoe
AnswerC

useradd creates a new user. The -m option creates the home directory (typically /home/jdoe) and copies skeleton files. The -s option sets the login shell to /bin/bash. This command creates the account with the specified home directory and shell, meeting all requirements.

Why this answer

The useradd command with -m creates the home directory and -s sets the shell. This is the standard non-interactive method to create a user with specific home and shell. The other commands either modify existing users, create groups, or are distribution-specific interactive tools that may not accept the given options.

Exam trap

The trap here is confusing useradd with usermod or groupadd, or assuming adduser is universally available with the same options across all distributions.

126
MCQmedium

An administrator needs to give a user read and write access to a file without changing the file's group or adding the user to any group. Which method should be used?

A.chown user: file
B.chmod u+rw file
C.setfacl -m u:username:rw file
D.chgrp to user's primary group
AnswerC

Using `setfacl -m u:username:rw file` writes a POSIX access control list entry granting that named user read and write permission, satisfying the stem's constraint of avoiding group changes or group membership edits. Standard Unix mode bits cannot grant per-user rights without altering owner, group or other classes, so ACLs are the only mechanism here.

Why this answer

Access Control Lists (ACLs) allow granting permissions to specific users or groups beyond the traditional owner/group/other model. The command 'setfacl -m u:username:rw file' adds a named user entry to the file's ACL, giving that user read and write access without altering the file's group ownership or requiring group membership changes. This is the standard Linux method for per-user granular permissions.

Exam trap

The trap here is confusing chmod's u+rw (which affects the file owner) with granting permissions to a different user; candidates often forget that traditional chmod cannot target arbitrary users, which is precisely why ACLs exist.

How to eliminate wrong answers

Option A is wrong because 'chown user: file' changes the file's owner to the specified user, which is a broader ownership change than granting access and does not preserve the original owner. Option B is wrong because 'chmod u+rw file' modifies the permissions of the file's current owner (the 'u' refers to owner), not an arbitrary user, so it would not grant the target user access unless they already own the file. Option D is wrong because 'chgrp' changes the file's group ownership, which alters group-level access and does not add the user to any group or grant them individual access.

127
Multi-Selectmedium

A user has a file with permissions set to 644. Which of the following commands will add the setuid permission to the file? (Choose two.)

Select 2 answers
A.chmod u+s file
B.chmod g+s file
C.chmod 1644 file
D.chmod 4644 file
E.chmod 2644 file
AnswersA, D

`chmod u+s file` sets the setuid bit on the file's owner-execute position, satisfying the stem's requirement to add setuid to a 644 file. The symbolic `u+s` form targets only the user (owner) permission triad, leaving the existing read and write bits untouched, which is precisely the operation requested.

Why this answer

Option A, chmod u+s file, is correct because the u+s symbolic mode adds the setuid bit to the user (owner) permission triad, which is exactly the setuid permission requested. Option D, chmod 4644 file, is correct because in the four-digit octal notation the leading digit represents special permissions, and the value 4 in that position is the setuid bit, so 4644 sets setuid while preserving the existing 644 rw-r--r-- permissions. Option B, chmod g+s file, is wrong because g+s sets the setgid bit on the group triad, not setuid.

Option C, chmod 1644 file, is wrong because the leading 1 sets the sticky bit, not setuid. Option E, chmod 2644 file, is wrong because the leading 2 sets the setgid bit, not setuid.

Exam trap

The trap here is confusing the octal values for setuid (4000), setgid (2000), and sticky (1000); candidates often pick 2644 or 1644 by mixing up which bit corresponds to which special permission.

128
MCQmedium

An administrator needs to replace all occurrences of 'oldhost' with 'newhost' in the configuration file /etc/hosts. Which command will perform the replacement and save the changes directly to the file?

A.sed 's/oldhost/newhost/g' /etc/hosts
B.awk '{gsub(/oldhost/,"newhost")}1' /etc/hosts
C.grep -r 'oldhost' /etc/hosts | sed 's/oldhost/newhost/g'
D.sed -i 's/oldhost/newhost/g' /etc/hosts
AnswerD

The `-i` flag makes sed edit /etc/hosts in place, satisfying the requirement to save changes directly to the file. The `g` suffix replaces every occurrence of 'oldhost' on each line, not merely the first, meeting the "all occurrences" constraint without redirection or a temporary file.

Why this answer

The `-i` flag (in-place editing) tells `sed` to write the changes directly back to the file specified. Without `-i`, `sed` only prints the modified output to stdout and does not alter the original file. The substitution command `s/oldhost/newhost/g` performs a global replacement of all occurrences of 'oldhost' with 'newhost' on each line.

Exam trap

The trap here is that candidates often forget the `-i` flag for in-place editing, assuming `sed` modifies the file by default, or they confuse `sed`'s stream behavior with editors like `vim` that directly change the file.

How to eliminate wrong answers

Option A is wrong because it omits the `-i` flag, so the replacement is performed on the stream and printed to stdout, but the original /etc/hosts file remains unchanged. Option B is wrong because `awk` by default writes to stdout only; it does not have an in-place editing flag, so the file is not saved. Option C is wrong because `grep -r` recursively searches for 'oldhost' in /etc/hosts (which is a single file, not a directory) and pipes matching lines to `sed`, but `sed` again lacks `-i` and the pipeline only processes matched lines, not the entire file, so the original file is not modified.

129
MCQeasy

A Linux administrator needs to change the hostname of a system to 'webserver01' permanently. The system uses systemd. Which command should the administrator use?

A.hostname webserver01
B.sysctl kernel.hostname=webserver01
C.hostnamectl set-hostname webserver01
D.echo webserver01 > /etc/hosts
AnswerC

hostnamectl set-hostname updates the system hostname and writes it to /etc/hostname, ensuring persistence across reboots. It is the recommended method on systemd-based distributions. This command also updates the transient hostname immediately, so the change takes effect without a reboot.

Why this answer

On systemd-based systems, hostnamectl set-hostname is the correct command to permanently change the hostname. It updates the static hostname in /etc/hostname and applies the change immediately. Other methods either change only the runtime hostname or modify unrelated configuration files.

Exam trap

The trap here is assuming that editing /etc/hosts or using the hostname command alone will persist the change, but only hostnamectl writes to the appropriate configuration.

130
MCQmedium

A Linux system has a directory with permissions drwxr-xr-x. A user in the group 'dev' tries to create a new file inside this directory. Which permission is missing that prevents the user from creating the file?

A.Write permission for the owner
B.Sticky bit is set
C.Write permission for the group
D.Execute permission for the group
AnswerC

Creating a file requires write permission on the containing directory, not on the file itself. The group permission set is r-x, granting read and execute (traverse) but withholding write. Adding group write (rwx) satisfies the stem's constraint, allowing the 'dev' group member to create entries within that directory.

Why this answer

The directory has write permission for the owner, but only read and execute for the group. To create a file, the user needs write permission on the directory, which is not granted to the group.

131
MCQmedium

An administrator needs to add an ACL entry to a file that grants the user 'john' read and write permissions. The file currently has no ACLs. Which command should the administrator use?

A.chmod u+rw file
B.setfacl -x u:john file
C.setfacl -m u:john:rw file
D.getfacl -m u:john:rw file
AnswerC

setfacl with -m modifies the ACL, and u:john:rw grants john read and write. Since the file has no existing ACLs, this creates the access ACL entry directly, satisfying the requirement without altering the traditional owner, group or other permission bits.

Why this answer

The correct command is setfacl -m u:john:rw file. setfacl is used to modify ACLs. getfacl is used to display ACLs and does not support a -m option for modifying ACLs on standard Linux systems.

← PreviousPage 2 of 2 · 131 questions total

Ready to test yourself?

Try a timed practice session using only System Management questions.