mediumMultiple Choice
XK0-006 Practice Question: Refer to the exhibit
Exhibit
ls -la /var/log/syslog -rw-r----- 1 syslog adm 1024000 Mar 10 12:45 /var/log/syslog df -h /var/log Filesystem Size Used Avail Use% Mounted on /dev/sda1 20G 19G 1.0G 95% / tail -5 /var/log/syslog Mar 10 12:44:59 server rsyslogd: [origin software="rsyslogd" swVersion="8.2106.0" x-pid="789" x-info="https://www.rsyslog.com"] start Mar 10 12:45:00 server rsyslogd: problem with file /var/log/syslog: No space left on device Mar 10 12:45:00 server rsyslogd: [origin software="rsyslogd" swVersion="8.2106.0" x-pid="789" x-info="https://www.rsyslog.com"] rsyslogd: HUP received, trying to restart.
Refer to the exhibit. The system log is not updating. What is the cause?
⚠ Common exam trap
XK0-006 often tests the misconception that a stopped log means the logging daemon crashed or lost its config, when the actual cause is usually environmental — full disk, read-only remount, or SELinux denial — that the exhibit's df output reveals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The root filesystem is almost full, leaving no space for log growth.
A full root filesystem prevents rsyslogd from writing new entries to /var/log, so the log appears frozen even though the daemon is running. The exhibit (df output showing / at or near 100%) is the giveaway — syslog cannot append when there is no free space, and the kernel may also stop writing to /var/log/messages. Freeing space or moving logs to a separate volume restores logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The syslog file size exceeded 1GB and was rotated.
Why it's wrong here
Log rotation renames the active file and creates a fresh one, so logging continues; the exhibit would show a rotated archive alongside a current, growing file. Rotation is expected housekeeping, not a fault, and would be the answer only if the new file were missing or unwritable.
- ✗
The syslog file permissions are incorrect.
Why it's wrong here
Incorrect permissions on the log file would typically produce a permission-denied error rather than silent non-updating, and the exhibit points to a different cause. It is tempting because file permissions are a common syslog failure, and they would be the answer if the daemon logged errors about being unable to open or write the target file.
- ✓
The root filesystem is almost full, leaving no space for log growth.
Why this is correct
A full root filesystem leaves no free blocks for rsyslog or journald to append entries, so logging silently stalls while other services continue running. The stem's symptom—a system log that has stopped updating—directly matches exhausted disk space on the partition holding /var/log, which is the constraint this option satisfies.
- ✗
rsyslogd was restarted and lost its configuration.
Why it's wrong here
rsyslogd reads its configuration at startup, so a restart reloads the same rules rather than discarding them; the daemon would still write to configured destinations. Restarting is relevant when a configuration change must take effect, not as a cause of silent logging failure.
Go deeper
Related to this question
Learn chapter
Navigating the Filesystem
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
Key term
Output
In IT service management, output is the result or deliverable produced by a process, system, or component, such as data, reports, or services delivered to a customer.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.