Courseiva

CCNA Troubleshooting Questions

75 of 105 questions · Page 1/2 · Troubleshooting topic · Answers revealed

1
MCQmedium

An administrator wants to monitor disk I/O performance in real-time, focusing on metrics like wait time and I/O queue size. Which tool is best suited for this?

A.vmstat
B.sar -b
C.free -h
D.iostat -x 1
AnswerD

The -x flag extends iostat output to include per-device metrics such as average wait time (await) and queue size (aqu-sz), while the interval argument 1 refreshes these statistics every second, satisfying the real-time monitoring requirement in the stem.

Why this answer

iostat -x 1 provides extended disk statistics refreshed every second, including await (average wait time), svctm, %util, and avgqu-sz (average queue size), which directly match the requested metrics. The -x flag enables the extended report that exposes per-device wait and queue depth, making it the correct real-time tool.

Exam trap

XK0-006 often tests the distinction between real-time per-device tools (iostat -x) and aggregate or historical tools (vmstat, sar), so candidates who pick vmstat for 'wait time and queue size' fall into the trap of confusing summary I/O counters with extended device metrics.

How to eliminate wrong answers

Option A is wrong because vmstat reports CPU, memory, paging, and block I/O counts but does not expose per-device wait time or I/O queue size. Option B is wrong because sar -b reports historical block I/O activity rates (tps, rtps, wtps, bread/s, bwrtn/s) from collected data, not real-time per-device queue metrics. Option C is wrong because free -h only displays memory and swap usage and has nothing to do with disk I/O.

2
MCQmedium

A technician needs to check the kernel ring buffer for hardware errors detected during system boot. Which command should be used?

A.journalctl -k
B.lspci
C.dmesg
D.cat /var/log/boot.log
AnswerC

dmesg reads the kernel ring buffer, exposing hardware detection and driver messages logged during boot, including errors. This directly satisfies the requirement to inspect boot-time hardware faults, unlike journalctl or log files that may not capture early kernel output.

Why this answer

The kernel ring buffer contains messages emitted by the kernel, including hardware detection and error messages during boot. The 'dmesg' command reads and prints this buffer directly. It is the canonical tool for inspecting kernel-level hardware errors, driver initialization failures, and boot-time device detection.

Exam trap

The trap is that candidates pick 'journalctl -k' because it also shows kernel messages, but the question asks for the kernel ring buffer specifically, and dmesg is the direct tool for that buffer.

How to eliminate wrong answers

Option A is wrong because 'journalctl -k' also shows kernel messages, but it reads from the systemd journal, which may not capture all early boot messages if the journal is not persistent or if the kernel buffer has wrapped; dmesg reads the kernel ring buffer directly and is the traditional, reliable tool for this purpose. Option B is wrong because 'lspci' lists PCI devices and their details but does not show kernel error messages or boot-time hardware errors. Option D is wrong because '/var/log/boot.log' contains boot-time service messages from the init system, not kernel hardware error messages, and it may not exist on all distributions.

3
MCQeasy

A Linux administrator needs to check which services are listening on TCP port 22. Which command should be used?

A.ss -tlnp | grep :22
B.ping -p 22 localhost
C.ip addr show port 22
D.traceroute -p 22 localhost
AnswerA

ss -tlnp lists TCP sockets in listening state with numeric ports and the owning process, and the grep filter narrows output to port 22. This satisfies the stem's constraint of identifying services listening on TCP 22, showing the sshd process bound to that port.

Why this answer

The 'ss' command (socket statistics) with the -tlnp flags lists TCP (-t) listening (-l) sockets with numeric ports (-n) and the owning process (-p). Piping to grep :22 filters for port 22, showing which service is listening on SSH. This is the modern replacement for netstat and is available on all current Linux distributions.

Exam trap

XK0-006 often tests the confusion between network diagnostic tools (ping, traceroute) and socket inspection tools (ss, netstat, lsof) — candidates must recognize that only ss/netstat/lsof can show listening services.

How to eliminate wrong answers

Option B is wrong because 'ping -p 22' sets the pattern of bytes in ICMP echo packets — it does not probe TCP port 22 and cannot identify listening services. Option C is wrong because 'ip addr show' displays IP addresses on interfaces; it has no concept of ports or listening services. Option D is wrong because 'traceroute -p 22' sets the destination UDP port for traceroute probes — it traces the network path, not local listening services.

4
Multi-Selectmedium

A Linux server reports that its root filesystem is 100 percent full, and applications are failing to write logs. The administrator needs to identify what is consuming space and reclaim it safely. Which two commands are appropriate to determine where the space is used? (Choose two.)

Select 2 answers
A.lsblk -f
B.df -i /
C.find / -xdev -type f -size +500M -exec ls -lh {} \;
D.fsck -n /dev/sda1
E.du -xh --max-depth=1 / | sort -h
AnswersC, E

This locates individual files larger than 500 MB while staying on the root filesystem thanks to -xdev, then lists them with sizes. Large single files such as runaway logs or core dumps are common causes of a full root volume, and this command pinpoints them quickly for review before deletion.

Why this answer

Finding what filled the root filesystem requires two complementary views: per-directory totals to narrow the search, and a scan for unusually large individual files. Staying on one filesystem with -x and -xdev prevents mounted volumes from skewing results. Together these commands point the administrator to the exact data to review or remove.

Exam trap

The trap here is reaching for inode or block-device listings, which describe filesystem structure and capacity rather than identifying which directories and files actually consumed the space.

5
MCQmedium

A system administrator wants to review kernel-related log messages from the current boot session. Which journalctl command should be used to filter the kernel messages?

A.journalctl -p err
B.journalctl -b -u systemd-journald
C.journalctl -k
D.journalctl --since today
AnswerC

The -k flag restricts journalctl output to kernel messages only, drawing from the kernel ring buffer captured by systemd-journald. This directly satisfies the requirement to isolate kernel-related entries from the current boot session, excluding user-space service and application logs.

Why this answer

journalctl -k shows kernel messages from the current boot.

6
MCQmedium

A Linux system is running slowly with high I/O wait as shown by vmstat. To investigate the I/O activity of a specific process that is suspected of causing the bottleneck, which of the following commands would be used to trace its system calls related to I/O?

A.iostat -x 1
B.strace -p <pid>
C.dmesg | tail
D.free -h
AnswerB

'strace -p <pid>' attaches to the running process and traces its system calls, exposing read, write and fsync activity that drives I/O wait. This satisfies the requirement to investigate a specific suspect process rather than system-wide I/O statistics.

Why this answer

strace attaches to a running process and traces its system calls, including I/O-related calls like read, write, open, and fsync, making it the right tool to pinpoint which syscalls a specific process is issuing. By using 'strace -p <pid>', the administrator can observe the exact I/O behavior of the suspect process. This directly addresses the need to trace system calls related to I/O for a specific PID.

Exam trap

XK0-006 often tests the distinction between system-wide I/O monitoring tools (iostat, vmstat) and per-process syscall tracing tools (strace), and candidates may pick iostat when the question specifically asks for tracing a process's system calls.

How to eliminate wrong answers

Option A is wrong because iostat -x 1 reports per-device I/O statistics at the system level, not per-process system calls, so it cannot attribute I/O to a specific process. Option C is wrong because dmesg | tail shows kernel ring buffer messages (hardware errors, driver messages), not per-process I/O syscall activity. Option D is wrong because free -h displays memory usage, which is unrelated to tracing a process's I/O system calls.

7
MCQhard

After applying a kernel update, a Linux server boots but the root filesystem is mounted read-only, and dmesg shows I/O errors on /dev/sda2. The administrator needs to determine whether the filesystem is corrupted and, if so, repair it safely. Which sequence of actions should the administrator take?

A.Recreate the filesystem with mkfs.ext4 /dev/sda2 and restore from the most recent backup.
B.Boot into rescue mode, run fsck -n on /dev/sda2 first, then run fsck -y if errors are reported.
C.Remount the root filesystem read-write with mount -o remount,rw / and continue using the server.
D.From the running system, run fsck -y /dev/sda2 immediately to repair the errors.
AnswerB

Booting to rescue mode ensures the root filesystem is not mounted, which is required for a safe check. fsck -n performs a read-only check and reports problems without modifying anything; if errors appear, fsck -y repairs them automatically. This order verifies corruption before committing changes.

Why this answer

A read-only root mount after I/O errors usually means the kernel detected filesystem problems and remounted defensively. Repair requires the filesystem to be offline, so rescue mode is appropriate. fsck -n first confirms and characterizes the damage without risk; if it reports errors, fsck -y applies repairs. Running fsck on a mounted filesystem, forcing a read-write remount, or reformatting are all unsafe or premature.

Exam trap

The trap here is running fsck -y directly on the mounted root filesystem, which can turn recoverable corruption into permanent data loss.

8
MCQhard

During boot, a Linux system displays a kernel panic with the message 'VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.Incorrect GRUB timeout setting
B.A faulty RAM module causing memory errors
C.Corrupted initramfs missing necessary storage drivers
D.Filesystem corruption on the boot partition
AnswerC

The initramfs carries the storage drivers needed to mount the root filesystem. If it is corrupted or lacks the correct driver, the kernel cannot locate the root device, producing exactly this unknown-block(0,0) panic before init runs.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates the kernel cannot locate or access the root filesystem. This is most commonly caused by a corrupted or missing initramfs that lacks the necessary storage drivers (e.g., for SATA, NVMe, or LVM) to communicate with the root device. Without these drivers, the kernel cannot read the root filesystem, resulting in a panic.

Exam trap

The trap here is that candidates often confuse this error with filesystem corruption on the boot partition (Option D), but the 'unknown-block(0,0)' message specifically points to the kernel's inability to find the root device, which is a driver/module issue in the initramfs, not a filesystem problem.

How to eliminate wrong answers

Option A is wrong because an incorrect GRUB timeout setting only affects the boot menu delay, not the kernel's ability to mount the root filesystem. Option B is wrong because a faulty RAM module typically causes random crashes, segmentation faults, or memory errors, not a specific VFS mount failure with an unknown block device. Option D is wrong because filesystem corruption on the boot partition would prevent GRUB from loading the kernel or initramfs, but the error here occurs after the kernel is loaded and fails to mount the root filesystem, indicating the initramfs is the issue.

9
Multi-Selectmedium

A Linux technician is troubleshooting a system that is experiencing high disk I/O wait times. Which TWO commands can be used to identify disk I/O performance issues? (Choose two.)

Select 2 answers
A.lsof
B.vmstat
C.iostat
D.free -h
E.dmesg
AnswersB, C

vmstat reports run-queue, blocked-process and CPU columns including wa (I/O wait), letting the technician confirm whether processes are stalled on disk. Its r and b columns distinguish CPU saturation from storage-bound waiting, directly addressing the high I/O wait symptom.

Why this answer

Option B (vmstat) is correct because it reports virtual memory statistics including the 'wa' (I/O wait) column in its CPU breakdown, which directly shows the percentage of time the CPU spent waiting on disk I/O, making it ideal for diagnosing high I/O wait times. Option C (iostat) is correct because it is specifically designed to report per-device and per-partition disk I/O statistics such as tps, kB_read/s, kB_wrtn/s, and %util, which pinpoint which block devices are saturated. Option A (lsof) lists open files and the processes using them, which can hint at file usage but does not measure disk I/O performance or wait times.

Option D (free -h) only displays memory and swap usage in human-readable form, providing no direct disk I/O metrics. Option E (dmesg) shows kernel ring buffer messages, useful for hardware or driver errors, but it does not report ongoing disk I/O performance statistics.

Exam trap

XK0-006 often tests the confusion between memory tools (free), file tools (lsof), and kernel log tools (dmesg) versus the actual I/O performance tools (vmstat, iostat, iotop).

10
Multi-Selecthard

A system fails to boot with a kernel panic. The administrator wants to recover by accessing a root shell. Which THREE methods can be used to achieve this?

Select 3 answers
A.Run 'fsck /dev/sda1' from the GRUB command line
B.Append 'single' to the kernel command line in GRUB
C.Press 'e' in GRUB and remove 'quiet'
D.Append 'rd.break' to the kernel command line in GRUB
E.Boot from a live CD and chroot into the installed system
AnswersB, D, E

Appending 'single' boots the kernel into single-user mode, which starts a root shell without launching the full init sequence. This bypasses the failing services that caused the panic, directly satisfying the requirement to reach a root shell for recovery.

Why this answer

Option B is correct because appending 'single' (or '1') to the kernel command line in GRUB boots the system into single-user/rescue mode, which starts a root shell without requiring the normal login and is a standard recovery method. Option D is correct because appending 'rd.break' to the kernel command line interrupts the boot process in the initramfs (dracut) before the root filesystem is mounted, dropping the administrator into a root shell where the real root can be mounted and repaired. Option E is correct because booting from a live CD/USB and then chrooting into the installed system's root filesystem gives a root shell with access to the broken system's files and tools, allowing repairs such as reinstalling GRUB or fixing /etc/fstab.

Option A is incorrect because 'fsck /dev/sda1' is not a valid GRUB command-line operation for obtaining a root shell; GRUB's command line is for bootloader commands, not for running filesystem checks as a recovery shell. Option C is incorrect because pressing 'e' in GRUB only opens the menu entry for editing and removing 'quiet' merely changes console verbosity; it does not by itself provide a root shell.

Exam trap

The trap here is that candidates may confuse the GRUB command line with a Linux shell, mistakenly thinking filesystem repair commands like fsck can be run directly from GRUB, or they may think removing 'quiet' alone grants root access when it only affects verbosity.

11
MCQhard

A server fails to boot with a kernel panic after a system update. The administrator suspects a corrupt initramfs. Which GRUB boot parameter should be added temporarily to boot into an emergency shell where the filesystem can be repaired?

A.rd.break
B.emergency
C.single
D.nomodeset
AnswerA

rd.break interrupts boot before the initramfs hands control to systemd, dropping into a switch_root emergency shell with the real root mounted read-only at /sysroot. This lets the administrator remount it read-write and repair the corrupt initramfs, satisfying the temporary-boot-parameter constraint.

Why this answer

rd.break is a kernel boot parameter that interrupts the boot process before the initramfs switches control to the real root filesystem, dropping the administrator into a debug shell (switch_root prompt). From there, the root filesystem can be mounted read-write and repaired, or the initramfs regenerated. This is the standard RHEL/CentOS method for recovering from a corrupt initramfs or forgotten root password.

Exam trap

XK0-006 often tests the distinction between rd.break (initramfs-stage break) and emergency/single (systemd-stage targets), so candidates must recognize that a corrupt initramfs requires breaking before switch_root.

How to eliminate wrong answers

Option B is wrong because emergency is a systemd target (emergency.target) that is reached after the initramfs has already handed off to the real root — if the initramfs is corrupt, the system may not reach it. Option C is wrong because single (or single-user mode) also requires a functioning initramfs to mount the root filesystem and start systemd in rescue mode. Option D is wrong because nomodeset only disables kernel mode setting for graphics drivers and has nothing to do with initramfs repair or emergency shell access.

12
MCQmedium

A technician needs to check the current memory usage on a Linux system, including buffers and cache. Which command provides the most user-friendly output?

A.free -h
B.cat /proc/meminfo
C.iostat -m
D.vmstat -s
AnswerA

free -h reports total, used, free, shared, buffer/cache and available memory, with the -h flag scaling values into human-readable units. That satisfies the user-friendly requirement while still exposing buffers and cache, which plain free shows only in kilobytes.

Why this answer

The `free -h` command displays memory usage in a human-readable format (e.g., KiB, MiB, GiB) and explicitly breaks down total, used, free, shared, buffers/cache, and available memory. This makes it the most user-friendly option for quickly assessing current memory usage including buffers and cache.

Exam trap

The trap here is that candidates may choose `cat /proc/meminfo` because it contains all the raw data, but the question specifically asks for the 'most user-friendly' output, which `free -h` provides with its human-readable scaling and clear summary columns.

How to eliminate wrong answers

Option B is wrong because `cat /proc/meminfo` provides raw, detailed memory statistics in a machine-readable format without any human-friendly scaling or summary, making it less user-friendly for a quick check. Option C is wrong because `iostat -m` reports CPU and I/O statistics (in megabytes), not memory usage, buffers, or cache. Option D is wrong because `vmstat -s` displays a summary of virtual memory statistics (including paging, swapping, and CPU events) but does not present buffers/cache in a clear, human-readable layout like `free -h`.

13
MCQhard

An administrator is troubleshooting a service that fails to start. They want to trace the system calls made by the service binary. Which command should they use?

A.ltrace
B.dmesg
C.strace
D.lsof
AnswerC

strace attaches to the process and prints each system call with arguments and return values, exposing where startup fails, such as a missing file or denied permission. It satisfies the requirement to trace system calls made by the service binary.

Why this answer

strace traces system calls and signals. It is used to debug what a program is doing at the kernel level.

14
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service's unit file has a dependency on another service, but the dependent service is not running. The administrator wants to view the dependency tree of the failing service to understand the ordering and requirements. Which command should be used?

A.systemctl list-dependencies failing.service
B.systemctl cat failing.service
C.journalctl -u failing.service
D.systemctl status failing.service
AnswerA

systemctl list-dependencies displays a tree of the specified unit's dependencies, including requires, wants, and after/before relationships. This directly shows the administrator which services the failing unit depends on and their current state, helping identify the missing dependency.

Why this answer

systemctl list-dependencies is specifically designed to show the dependency tree of a unit, including which units are required or wanted and their current states. It provides a clear hierarchical view that helps diagnose why a service fails due to unmet dependencies. Other commands show status or logs but not the dependency structure.

Exam trap

The trap here is assuming that systemctl status or journalctl will show the full dependency tree; they only show symptoms or configuration, not the runtime dependency hierarchy.

15
MCQmedium

A Linux administrator is investigating why a scheduled backup job did not run overnight. The job is defined in the root user's crontab. Which command should the administrator use to review the cron daemon's log entries for the relevant time period?

A.crontab -l -u root
B.atq
C.journalctl -u cron --since "yesterday"
D.systemctl list-timers --all
AnswerC

On systems using systemd, the cron daemon runs as a unit, so journalctl -u cron retrieves its log entries. Adding --since "yesterday" limits output to the relevant window. This shows whether cron attempted to start the job, any errors it logged, and whether the job was skipped. It directly addresses why the scheduled backup did not execute.

Why this answer

To determine why a cron job did not execute, the administrator must examine the cron daemon's logs for the relevant period. On systemd-based distributions, cron is managed as a unit, so journalctl -u cron with a time filter surfaces start attempts, command errors, and skipped jobs. Listing the crontab or checking unrelated schedulers does not provide execution history.

Exam trap

The trap here is verifying the crontab definition instead of checking daemon logs, which is where evidence of whether the job actually ran and any errors it produced is recorded.

16
Multi-Selectmedium

A Linux server becomes unresponsive, and the administrator suspects a process is consuming excessive CPU. The administrator needs to identify the offending process and then terminate it cleanly by PID. Which TWO commands should be used to accomplish these tasks? (Choose two.)

Select 2 answers
A.top
B.nohup ./service &
C.killall -9 bash
D.kill -SIGTERM <PID>
E.lsof -i :80
AnswersA, D

top displays a live, sorted view of processes with CPU and memory usage, defaulting to the highest CPU consumers at the top. It lets the administrator quickly identify the process name and its PID during an active incident. This directly satisfies the requirement to find the process driving CPU usage before acting on it.

Why this answer

Identifying a CPU hog requires a live process viewer that sorts by CPU, and top provides exactly that with PIDs. Once the PID is known, sending SIGTERM with kill requests an orderly shutdown so the process can release resources. Together these two steps find and cleanly stop the offending process, matching the scenario without resorting to a forceful, name-based kill.

Exam trap

The trap here is reaching for killall or kill -9, which act by name or forcefully, instead of identifying the PID and requesting a graceful SIGTERM.

17
MCQeasy

A system administrator wants to collect network performance statistics over time, including packet loss and latency, to diagnose intermittent connectivity issues. Which tool combines the functionality of ping and traceroute into a single continuous monitoring command?

A.mtr
B.tcpdump
C.ss
D.netstat
AnswerA

mtr continuously combines ping and traceroute by repeatedly probing each hop, refreshing latency and packet-loss statistics in real time. This satisfies the requirement for ongoing monitoring of intermittent connectivity, unlike one-shot ping or traceroute, which capture only a single snapshot and would miss transient faults.

Why this answer

mtr (My TraceRoute) continuously sends packets and displays real-time statistics including loss and latency for each hop, combining ping and traceroute.

18
MCQmedium

A Linux administrator notices that a server's root filesystem is filling up rapidly. After running `df -h`, the root filesystem shows 100% usage. However, when the administrator runs `du -sh /*` from the root directory, the total size is only about 40% of the filesystem. The administrator suspects that a deleted file is still being held open by a process. Which command should the administrator use to identify the process holding the deleted file?

A.ls -l /proc/*/fd | grep deleted
B.fuser -mv /
C.lsof +L1
D.find / -inum 0 -print
AnswerC

The `lsof +L1` command lists open files with a link count less than 1, which indicates files that have been unlinked (deleted) but are still held open by a process. This directly addresses the scenario where deleted files consume space. It will show the process name and PID, allowing the administrator to restart the process and free the space.

Why this answer

The `lsof +L1` command is specifically designed to list open files with a link count less than 1, meaning they have been deleted but are still held open by a process. This is the most direct and reliable way to identify the process causing the disk space discrepancy. Other commands may show open files but do not target deleted files specifically.

Exam trap

The trap here is assuming that `du` and `df` should always match, but they can differ when a process holds a deleted file open, and only `lsof +L1` directly reveals this condition.

19
MCQmedium

An administrator wants to capture network traffic on interface eth0, writing the output to a file for later analysis, without resolving hostnames. Which command accomplishes this?

A.tcpdump -i eth0 -r capture.pcap
B.tcpdump -i eth0 -w capture.pcap -n
C.tcpdump -i any -w capture.pcap
D.tcpdump -n -w eth0 capture.pcap
AnswerB

The `-i eth0` flag binds capture to the specified interface, `-w capture.pcap` writes raw packets to a file rather than printing them, and `-n` suppresses DNS and service-name resolution, satisfying the no-hostname constraint. Together these flags match every requirement in the stem.

Why this answer

tcpdump -i eth0 -w capture.pcap -n captures packets on interface eth0, writes them to capture.pcap for later analysis, and the -n flag prevents hostname resolution (shows IP addresses instead). This matches all three requirements: interface selection, file output, and no name resolution.

Exam trap

XK0-006 often tests the difference between -w (write to file) and -r (read from file), and the meaning of -n (no name resolution) — candidates frequently swap -w and -r or forget that -n is required to suppress hostname lookups.

How to eliminate wrong answers

Option A is wrong because -r reads from a capture file rather than writing to one, and it does not capture live traffic. Option C is wrong because -i any captures on all interfaces, not specifically eth0, and it omits the -n flag so hostnames would be resolved. Option D is wrong because the syntax is incorrect — -w expects a filename, not an interface, so 'tcpdump -n -w eth0 capture.pcap' would try to write to a file named eth0 and treat capture.pcap as a filter expression.

20
MCQhard

A user reports that an application fails with 'Permission denied' when writing to /srv/reports, even though the user is a member of the group that owns the directory. Running `ls -ld /srv/reports` returns 'drwxr-x--- 2 root reports 4096 Jun 10 09:14 /srv/reports'. The user's `id` output confirms membership in the reports group. Which action will allow the user to create files in that directory?

A.Run chmod u+w /srv/reports as root
B.Run chmod o+w /srv/reports as root
C.Run chown user:reports /srv/reports as root
D.Run chmod g+w /srv/reports as root
AnswerD

The permission string shows the group triad as r-x, meaning group members may read and traverse but not write. Because the user is confirmed in the owning group, granting the group write bit with chmod g+w directly resolves the denial without widening access to other users. This is the minimal, targeted change that matches the observed mode and group membership.

Why this answer

The mode string shows the group triad as r-x, so members of the reports group can list and enter the directory but cannot create entries. Since the user's group membership is verified, the correct fix is to add write permission to the group triad only. This grants exactly the needed capability while preserving the restrictive access for all other accounts.

Exam trap

The trap here is assuming that verified group membership is sufficient, when the group triad in the mode string must also carry the write bit for creation to succeed.

21
Multi-Selecthard

A Linux administrator is troubleshooting intermittent application failures on a server. They suspect resource exhaustion. Which TWO commands can be used to check current system resource limits and usage for a running process? (Choose two.)

Select 2 answers
A.nice -n 10 <command>
B.cat /proc/<PID>/status
C.ulimit -a
D.cat /proc/<PID>/limits
E.systemctl status <service>
AnswersB, D

The /proc/<PID>/status file includes the process's current resource usage fields such as VmRSS, Threads, and open file descriptor counts, along with many state details. Comparing these values against the limits in /proc/<PID>/limits helps confirm whether the process is approaching a ceiling. It provides a live snapshot of the specific process, which is exactly what is needed when investigating intermittent exhaustion of an already-running application.

Why this answer

Diagnosing resource exhaustion in an already-running process requires inspecting that process's effective limits and current usage. The /proc/<PID>/limits file lists the soft and hard limits the process actually runs under, while /proc/<PID>/status reports live usage counters such as resident memory and thread counts. Together they let the administrator compare usage against limits without relying on the current shell's settings.

Exam trap

The trap here is using ulimit -a, which only reflects the current shell, instead of inspecting the running process's own /proc entries where the effective limits are recorded.

22
MCQmedium

A Linux administrator is troubleshooting a server that has become unresponsive. They suspect a process is consuming excessive CPU. Which command should they use to display a real-time, interactive view of processes sorted by CPU usage?

A.iostat -c
B.vmstat 1
C.top
D.ps aux
AnswerC

The top command provides a dynamic, real-time view of running processes, typically sorted by CPU usage by default. It allows the administrator to identify processes with high CPU consumption, and it supports interactive commands to change sorting, kill processes, and more. This makes it ideal for live troubleshooting of CPU-bound issues on a server.

Why this answer

The top command is designed for real-time process monitoring, showing a continuously updated list of processes sorted by CPU usage. It allows an administrator to quickly spot which process is consuming the most CPU and take action, such as renice or kill. Other tools like ps provide only a snapshot, while vmstat and iostat give system-wide statistics without per-process breakdown.

Exam trap

The trap here is confusing static snapshot tools like ps with interactive, real-time monitors like top, which are needed for live CPU troubleshooting.

23
MCQeasy

A user reports that they cannot reach a website. The administrator wants to check the path that packets take to the destination server. Which command should be used?

A.ip addr
B.ss
C.traceroute
D.ping
AnswerC

traceroute sends packets with incrementally increasing TTL values, causing each router along the path to return an ICMP Time Exceeded message. This reveals the hop-by-hop route packets take to the destination, exactly what the administrator needs to diagnose where connectivity fails.

Why this answer

The `traceroute` command is used to trace the path packets take from the source to a destination host, showing each hop (router) along the way. It uses ICMP echo requests (or UDP packets on Linux) with incrementing TTL values to elicit ICMP Time Exceeded messages from intermediate routers, which reveals the network path. This directly addresses the administrator's need to check the path to the destination server.

Exam trap

In the Linux+ exam, candidates may confuse 'ping' with 'traceroute'. Ping only tests reachability and latency, while traceroute reveals the specific path and each hop. The trap is choosing ping because it can show connectivity issues, but it does not show the route.

How to eliminate wrong answers

Option A is wrong because `ip addr` displays IP addresses and network interface configuration on the local host, not the path packets take to a remote destination. Option B is wrong because `ss` (socket statistics) shows information about local sockets and connections, not the network path or routing hops. Option D is wrong because `ping` tests reachability and measures round-trip time using ICMP echo requests, but it does not show the intermediate hops or the path packets traverse.

24
MCQhard

An administrator is troubleshooting a service that fails to start with a 'Permission denied' error. The administrator runs `strace -f -o /tmp/strace.log systemctl start myservice`. Which of the following best describes what this command achieves?

A.It records the kernel messages related to the service start.
B.It traces system calls for systemctl and its children, recording them to a file.
C.It monitors network connections opened by the service.
D.It traces library calls made by the service startup.
AnswerB

strace attaches to systemctl and, with -f, follows forked child processes, while -o writes the captured system calls to /tmp/strace.log. This reveals the exact syscall returning EACCES, pinpointing the permission failure without flooding the terminal.

Why this answer

strace traces system calls; -f follows child processes; -o writes output to file.

25
MCQmedium

An administrator notices that a web application intermittently returns 'Connection timed out' to clients on the same subnet, while the server itself responds to pings. Packet captures show the server receiving SYN packets but never replying. The host firewall is suspected. Which command should the administrator use to inspect the active ruleset and its counters on a system using nftables?

A.ss -tlnp
B.nft list ruleset
C.iptables -L -n -v
D.tcpdump -i any port 80
AnswerB

On a system using nftables, nft list ruleset prints every table, chain, and rule in the current ruleset, including any counter expressions attached to rules. This lets the administrator see whether an input rule is dropping the SYN packets and confirm it via the counter values, directly matching the symptom of received-but-unanswered SYNs.

Why this answer

Because the server receives SYNs but never answers, filtering on inbound traffic is the leading hypothesis. On a native nftables host, listing the ruleset reveals both the rules and their counters, so the administrator can identify the offending drop or reject rule and confirm it is actually matching traffic. Compatibility tools may not reflect natively created rules.

Exam trap

The trap here is trusting iptables output on a host configured natively with nftables, where it may appear empty and falsely suggest no firewall rules exist.

26
MCQhard

A technician needs to trace the system calls made by a running process to debug a performance issue. Which tool should be used?

A.gdb -p PID
B.lsof -p PID
C.ltrace -p PID
D.strace -p PID
AnswerD

strace attaches to the running process identified by PID via -p and reports each system call it makes, exposing blocking calls, file or socket waits and repeated retries. This directly targets the performance issue by revealing kernel-level activity of that process.

Why this answer

`strace -p PID` intercepts and records system calls (kernel-level operations like file I/O, network, and process control) made by a running process, which is exactly what is needed to trace system calls for debugging performance issues. The `-p` flag attaches strace to an existing process by its PID, allowing real-time monitoring of kernel interactions.

Exam trap

The trap here is that candidates confuse `ltrace` (library calls) with `strace` (system calls), as both trace function calls but at different layers of the operating system stack.

How to eliminate wrong answers

Option A is wrong because `gdb -p PID` is a debugger for inspecting and modifying program state at the source-code or assembly level, not for tracing system calls; it focuses on user-space debugging, not kernel call tracing. Option B is wrong because `lsof -p PID` lists open file descriptors (files, sockets, pipes) for a process, but it does not trace system calls or their timing; it provides a static snapshot of open handles, not dynamic call tracing. Option C is wrong because `ltrace -p PID` traces library calls (user-space function calls to shared libraries like glibc), not system calls; it intercepts calls to dynamically linked library functions, whereas the question specifically asks for system calls.

27
MCQmedium

A system administrator is troubleshooting a network issue where a server cannot reach the internet. The server's IP address is 192.168.1.10/24, and the default gateway is 192.168.1.1. Which command should be used to verify the default gateway configuration?

A.ip neigh show
B.ip addr show
C.ip route show
D.ip link show
AnswerC

The server's routing table holds the default gateway entry, so 'ip route show' displays it directly, confirming whether 192.168.1.1 is configured as the default route for the 192.168.1.0/24 interface. This satisfies the requirement to verify gateway configuration rather than merely testing reachability.

Why this answer

The `ip route show` command displays the kernel's IPv4 routing table, which includes the default gateway entry (destination 0.0.0.0/0 via 192.168.1.1). This directly verifies whether the default gateway is configured correctly for the server to reach external networks.

Exam trap

The trap here is that candidates often confuse `ip addr show` (which shows IP addresses) with `ip route show` (which shows routing table), leading them to select the wrong command when asked to verify the default gateway.

How to eliminate wrong answers

Option A is wrong because `ip neigh show` displays the ARP cache (neighbor table), showing MAC-to-IP mappings for directly connected hosts, not the default gateway configuration. Option B is wrong because `ip addr show` displays IP addresses and interface properties, not routing information such as the default gateway. Option D is wrong because `ip link show` shows link-layer (Layer 2) interface status and MTU, not Layer 3 routing entries.

28
MCQmedium

A Linux administrator receives reports that a server becomes unresponsive for several seconds at a time. Running `uptime` shows a load average of 14.2 on a system with 4 CPU cores, and `vmstat 1` reports a steadily rising 'r' column with a 'wa' column near zero. Which command should the administrator run NEXT to identify which processes are consuming CPU time?

A.iostat -x 1
B.free -m
C.top -o %CPU
D.df -h
AnswerC

Running top sorted by CPU usage immediately surfaces the processes consuming the most processor time, which is exactly what a high run-queue count with negligible I/O wait points to. It refreshes live, so the administrator can watch the offending process and confirm whether a single runaway task or many busy tasks are driving the load average far above the four-core capacity.

Why this answer

A load average of 14.2 on four cores with a growing run queue and almost no I/O wait indicates CPU contention, not storage or memory pressure. The fastest way to attribute that contention is a live, CPU-sorted process view, which shows exactly which tasks are runnable and consuming cycles so the administrator can decide whether to renice, restart, or investigate further.

Exam trap

The trap here is assuming a high load average always means disk or memory trouble, when a large run queue with near-zero wait points squarely at CPU contention.

29
MCQmedium

A Linux administrator needs to verify which network interfaces are up and their IP addresses on a server. Which command provides this information?

A.ss -tlnp
B.nmcli dev show
C.ifconfig -a
D.ip addr
AnswerD

The ip addr command reads interface state and assigned addresses directly from the kernel, listing every interface with its UP/DOWN flag and IPv4/IPv6 addresses. It satisfies the requirement to verify which interfaces are up and their IPs.

Why this answer

The `ip addr` command displays all network interfaces along with their IP addresses, MAC addresses, and status (UP/DOWN).

30
MCQmedium

A user reports that a web server is unreachable. The administrator runs 'curl -I https://example.com' and gets no response. Which command should be used next to check if the server is reachable at the network level?

A.ping -c 4 example.com
B.dig -x example.com
C.lsof -i :443
D.ss -tlnp | grep 443
AnswerA

ping -c 4 example.com sends four ICMP echo requests, testing IP-level reachability independently of HTTPS. Since curl returned nothing, this isolates whether the host responds at the network layer before investigating TLS, DNS resolution or the web service itself.

Why this answer

The `curl -I` command failed to get a response, which could be due to a network-level issue rather than an application-layer problem. The `ping` command uses ICMP echo requests to test basic IP-level connectivity to the host, bypassing higher-layer protocols like HTTP/TLS. If the server is unreachable at the network layer, `ping` will show packet loss or timeouts, confirming a routing or firewall issue.

Exam trap

The trap here is that candidates may choose `ss` or `lsof` because they are familiar with checking local services, but these commands cannot test remote reachability, which is the core of the question.

How to eliminate wrong answers

Option B is wrong because `dig -x example.com` performs a reverse DNS lookup, which checks if an IP address resolves to a hostname, not whether the server is reachable at the network level. Option C is wrong because `lsof -i :443` lists local processes listening on TCP port 443, which only checks if a service is running locally, not if the remote server is reachable. Option D is wrong because `ss -tlnp | grep 443` shows local TCP listening sockets on port 443, which is a local diagnostic tool and cannot verify network-level reachability to a remote host.

31
MCQeasy

A Linux administrator receives reports that a server's root filesystem is completely full. They run `df -h` and see that the root partition is at 100% usage. Which command should they use NEXT to identify which directories are consuming the most space?

A.du -sh /* | sort -h
B.fdisk -l
C.find / -type f -size +1G
D.ls -la /
AnswerA

The `du -sh /*` command calculates the total disk usage of each top-level directory and displays it in human-readable format, while `sort -h` orders the results by size. This directly identifies which directories are consuming the most space, allowing the administrator to drill down further. It is the most efficient next step for locating large directories on a full filesystem.

Why this answer

When a filesystem is full, the administrator must first identify which directories are consuming the most space. The `du` command with the `-s` and `-h` options provides a summary of disk usage per directory, and piping to `sort -h` orders the results by size. This quickly highlights the largest directories, enabling efficient troubleshooting.

Exam trap

The trap here is confusing disk usage reporting tools: `df` shows filesystem-level usage, while `du` shows directory-level usage, and only `du` can pinpoint the directories consuming space.

32
MCQmedium

A Linux administrator is troubleshooting a server that cannot resolve hostnames. The administrator suspects a misconfiguration in the DNS resolver. Which file should be checked first to verify the DNS server addresses?

A./etc/nsswitch.conf
B./etc/hosts
C./etc/resolv.conf
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerC

/etc/resolv.conf lists the DNS servers (nameservers) that the system queries for hostname resolution. It is the primary configuration file for the resolver. Checking this file verifies which DNS servers are configured and if they are reachable. A missing or incorrect nameserver entry here would directly cause hostname resolution failures.

Why this answer

/etc/resolv.conf is the standard file for configuring DNS resolvers on Linux. It contains nameserver entries that specify the IP addresses of DNS servers. Checking this file directly verifies the DNS server addresses in use.

Other files may influence resolution but do not store the DNS server addresses themselves.

Exam trap

The trap here is assuming that DNS server addresses are stored in interface configuration files, but on most modern systems, /etc/resolv.conf is the authoritative resolver configuration file.

33
MCQmedium

A Linux administrator notices that a server's root filesystem is using 100% of its inodes, even though `df -h` shows only 60% of the disk space used. Users are unable to create new files. Which command most directly helps identify directories containing large numbers of small files that are consuming inodes?

A.find / -xdev -type f | wc -l
B.du -sh /*
C.du --inodes -s /* | sort -n
D.df -i
AnswerC

`du --inodes -s /*` summarizes inode counts for each top-level directory, and `sort -n` orders them numerically so the largest consumer appears last. This directly addresses inode exhaustion by pinpointing which directory tree holds the most inodes. Unlike disk-space tools, it counts inodes regardless of file size, making it ideal for finding directories filled with many small or empty files that exhaust the inode table.

Why this answer

The root filesystem has run out of inodes, not blocks, so tools that report disk space are ineffective. `du --inodes -s /*` followed by numeric sorting reveals which top-level directories contain the most inodes, allowing the administrator to drill down and remove unneeded small files. This approach directly targets the exhausted resource and avoids wasted effort on block-space analysis.

Exam trap

The trap here is assuming that disk-space tools like `df -h` or `du` will reveal an inode problem, when inode exhaustion is a separate resource that requires inode-aware commands such as `df -i` and `du --inodes`.

34
MCQhard

During boot, a Linux system displays a kernel panic indicating 'not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.Network configuration error
B.A failed filesystem check due to dirty file system
C.Incorrect GRUB timeout value
D.Missing or corrupt initramfs
AnswerD

The kernel mounts the root filesystem using drivers loaded from the initramfs. If that image is missing or corrupt, the required storage driver never loads, producing the unknown-block(0,0) panic. A missing or corrupt initramfs is therefore the likely cause.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates that the kernel cannot locate or access the root filesystem. This is most commonly caused by a missing or corrupt initramfs (initial RAM filesystem), which contains the necessary drivers and modules to mount the root filesystem. Without a valid initramfs, the kernel has no way to load storage drivers (e.g., for SATA, NVMe, or LVM) and thus fails to mount the root device.

Exam trap

Candidates often confuse a 'dirty filesystem' error with the 'unknown-block(0,0)' message; the latter is specifically about the kernel's inability to find the root device due to missing drivers in the initramfs.

How to eliminate wrong answers

Option A is wrong because a network configuration error would not prevent the kernel from mounting the root filesystem; network issues typically cause problems later in the boot process (e.g., during network service startup). Option B is wrong because a failed filesystem check due to a dirty filesystem would produce a different error (e.g., 'fsck failed' or 'mount: wrong fs type') and would not result in an 'unknown-block(0,0)' message, which indicates the block device itself is unrecognized. Option C is wrong because an incorrect GRUB timeout value only affects the boot menu countdown; it does not affect the kernel's ability to locate or mount the root filesystem.

35
Multi-Selecthard

A Linux server is experiencing intermittent network connectivity issues. The administrator needs to capture and analyze network traffic to diagnose the problem. Which TWO commands or tools can be used to capture packets on the eth0 interface? (Choose two.)

Select 2 answers
A.tcpdump -i eth0
B.netstat -i eth0
C.tshark -i eth0
D.nmap -sP 192.168.1.0/24
E.ss -t -a
AnswersA, C

tcpdump -i eth0 captures packets on the eth0 interface in real time. It is a standard command-line packet analyzer that allows filtering and inspection of network traffic. This directly addresses the need to capture packets for diagnosing intermittent connectivity issues. It provides detailed output that can be saved to a file for later analysis, making it a primary tool for network troubleshooting.

Why this answer

tcpdump and tshark are both packet capture tools that can operate on a specified interface like eth0. They allow real-time capture and analysis of network traffic, which is essential for diagnosing intermittent connectivity issues. The other commands provide statistics or connection lists but do not capture packets.

Exam trap

The trap here is confusing interface statistics or connection listings with actual packet capture tools; only tcpdump and tshark capture and record packet data.

36
MCQhard

A Linux administrator is troubleshooting a system that becomes unresponsive under heavy load. They suspect that a process is causing excessive disk I/O. Which command should the administrator use to identify the process performing the most disk writes in real time?

A.iotop -o
B.iostat -x 1
C.pidstat -d 1
D.vmstat 1
AnswerA

iotop -o displays only processes that are actively performing I/O, sorted by I/O usage. It provides real-time monitoring of disk read/write bandwidth per process, making it ideal for identifying the process causing heavy disk writes. The -o option filters out idle processes, focusing on active ones.

Why this answer

To identify the process causing heavy disk writes in real time, the administrator needs a tool that shows per-process I/O activity. iotop -o displays only active I/O processes, sorted by I/O usage, making it easy to spot the culprit. While pidstat -d can also show per-process I/O, iotop is specifically designed for interactive real-time monitoring and is more commonly used for this scenario.

Exam trap

The trap here is choosing a tool that shows disk activity but not per-process attribution, or assuming that any I/O monitoring tool provides per-process detail.

37
Multi-Selectmedium

An administrator is investigating a network issue where a server cannot connect to an external website. They run `ping 8.8.8.8` successfully, but `ping google.com` fails. Which TWO of the following are the most likely causes? (Choose TWO.)

Select 2 answers
A.The network interface is down.
B.The default gateway is misconfigured.
C.The DNS server is unreachable or misconfigured.
D.The firewall is blocking ICMP traffic.
E.The /etc/hosts file has an incorrect entry for google.com.
AnswersC, E

Successful pinging of 8.8.8.8 proves IP connectivity and routing work, isolating the fault to name resolution. An unreachable or misconfigured DNS server prevents resolving google.com to an IP address, exactly matching the symptom of numeric pings succeeding while hostname pings fail.

Why this answer

Option C is correct because the successful `ping 8.8.8.8` proves IP connectivity and routing to the internet work, while the failure of `ping google.com` indicates name resolution is failing — meaning the configured DNS server is unreachable, misconfigured, or not responding on port 53. Option E is correct because an incorrect entry for google.com in /etc/hosts would cause the resolver to return a wrong IP address for that hostname before ever querying DNS, producing exactly this symptom (numeric IP works, hostname fails). Option A is wrong because a down network interface would prevent even `ping 8.8.8.8` from succeeding.

Option B is wrong because a misconfigured default gateway would break routing to external IP addresses, so the numeric ping to 8.8.8.8 would also fail. Option D is wrong because a firewall blocking ICMP would cause both pings to fail, not just the hostname-based one.

Exam trap

XK0-006 often tests the diagnostic reasoning that successful IP ping plus failed hostname ping isolates the fault to name resolution, tempting candidates to blame routing or firewalls that would have broken both pings.

38
Multi-Selectmedium

A Linux administrator is troubleshooting a server that is unresponsive. They suspect a process is consuming excessive CPU. Which TWO commands can be used to identify the process with the highest CPU usage? (Choose two.)

Select 2 answers
A.vmstat 1
B.free -m
C.iostat -c
D.ps aux --sort=-%cpu | head -n 5
E.top
AnswersD, E

The `ps aux --sort=-%cpu` command lists all processes sorted by CPU usage in descending order, and piping to `head -n 5` shows the top five. This provides a snapshot of the processes with the highest CPU consumption. It is a non-interactive alternative to `top` and is useful for scripting or quick checks.

Why this answer

To identify a process consuming excessive CPU, the administrator needs tools that display per-process CPU usage. `top` provides a real-time, sorted list of processes by CPU usage. `ps aux --sort=-%cpu | head -n 5` gives a snapshot of the top CPU-consuming processes. Other commands like `free`, `vmstat`, and `iostat` show system-wide metrics but not per-process details.

Exam trap

The trap here is confusing system-wide CPU monitoring tools like vmstat and iostat with per-process tools like top and ps; only the latter can identify a specific process.

39
MCQhard

An administrator needs to capture network traffic on interface eth0, filter for packets to/from host 10.0.0.1, and save the output to a file for later analysis. Which command should be used?

A.tcpdump -i eth0 src 10.0.0.1 -w capture.pcap
B.tcpdump -i eth0 dst 10.0.0.1 -w capture.pcap
C.tcpdump -i eth0 host 10.0.0.1 -w capture.pcap
D.tcpdump -i eth0 -n host 10.0.0.1 -w capture.pcap
AnswerC

tcpdump -i eth0 host 10.0.0.1 -w capture.pcap binds capture to eth0, applies a host filter matching traffic in either direction to or from 10.0.0.1, and writes raw packets to capture.pcap for later analysis, satisfying all three requirements.

Why this answer

The `tcpdump` command with the `host` filter captures all traffic (both source and destination) to or from the specified IP address, which matches the requirement to filter for packets to/from host 10.0.0.1. The `-i eth0` specifies the interface, and `-w capture.pcap` writes the output to a file for later analysis.

Exam trap

The trap here is that candidates often confuse `src` and `dst` filters as sufficient for capturing all traffic to/from a host, forgetting that `host` is the correct primitive for bidirectional capture.

How to eliminate wrong answers

Option A is wrong because `src 10.0.0.1` only captures packets where the source IP is 10.0.0.1, missing packets destined to that host. Option B is wrong because `dst 10.0.0.1` only captures packets where the destination IP is 10.0.0.1, missing packets sourced from that host. Option D is wrong because the `-n` flag disables name resolution (which is not required by the question) but does not affect the filter; however, the primary issue is that it includes an unnecessary flag, and the question asks for the correct command, not an equivalent one with extra options.

40
MCQeasy

A Linux administrator needs to check which services are listening on TCP ports on a server. Which command should be used to replace the deprecated netstat command?

A.ss -tlnp
B.nmap localhost
C.ip link show
D.dig -t any localhost
AnswerA

The `ss -tlnp` command uses the `-t` flag to filter only TCP sockets, `-l` to show only listening sockets, `-n` to display numeric addresses and ports without DNS resolution, and `-p` to reveal the process identifier and name. This directly replaces `netstat -tlnp` by reading socket information from the kernel’s `/proc/net/tcp` and `/proc/net/tcp6` files, satisfying the stem’s requirement to check services listening on TCP ports.

Why this answer

The `ss` command is the modern replacement for `netstat`, providing socket statistics. The flags `-tlnp` specifically show TCP (`-t`) listening (`-l`) sockets with numeric ports (`-n`) and the process (`-p`) using them, which directly answers the administrator's need to see listening TCP ports and associated services.

Exam trap

The trap here is assuming that any command that can list network information (like nmap or ip) is a valid replacement for netstat, but only `ss` is designed as its direct successor with similar syntax and output.

How to eliminate wrong answers

Option B is wrong because `nmap localhost` performs a port scan, which may not show the listening process and is not a direct replacement for netstat; it also requires nmap to be installed. Option C is wrong because `ip link show` displays network interface information (Layer 2), not listening ports. Option D is wrong because `dig -t any localhost` queries DNS records for the hostname 'localhost', which is unrelated to listing listening TCP ports.

41
MCQhard

An administrator needs to trace system calls made by a process that is misbehaving. Which command should be used to attach to the running process and display its system calls?

A.tcpdump -i any
B.ltrace -p <PID>
C.strace -p <PID>
D.lsof -p <PID>
AnswerC

`strace -p <PID>` attaches to an already-running process via ptrace and prints each system call it makes, satisfying the requirement to trace a misbehaving process without restarting it. The `-p` flag targets the live PID directly, which is exactly what the scenario demands.

Why this answer

strace is the standard Linux utility for tracing system calls made by a process. Using strace -p <PID> attaches to an already-running process and displays its system calls in real time, which is exactly what is needed to diagnose a misbehaving process at the kernel interface level. This makes it the correct tool for observing file opens, reads, writes, network calls, and signal handling.

Exam trap

The trap is confusing strace (system calls) with ltrace (library calls) — candidates who don't distinguish kernel syscalls from userspace library calls pick ltrace, or they pick lsof thinking it traces activity when it only lists open resources.

How to eliminate wrong answers

Option A is wrong because tcpdump captures network packets, not system calls, and is used for network traffic analysis rather than process-level syscall tracing. Option B is wrong because ltrace traces library calls (such as calls into libc), not system calls, so it would not show the kernel-level syscalls the question asks for. Option D is wrong because lsof lists open files and network connections held by a process, providing a snapshot rather than a live trace of system calls.

42
MCQeasy

An administrator wants to check the amount of free memory and swap usage on a system in a human-readable format. Which command should be used?

A.free -h
B.vmstat -h
C.cat /proc/meminfo
D.iostat -h
AnswerA

'free -h' reads /proc/meminfo and prints total, used and available RAM alongside swap usage, with the -h flag scaling values into human-readable units such as MiB and GiB. This directly satisfies the requirement for readable free memory and swap figures.

Why this answer

The free command displays total, used, and available physical memory and swap space, and the -h flag formats the output in human-readable units such as MiB and GiB. This directly satisfies the requirement to check free memory and swap usage in a readable format. It is the standard Linux utility for this purpose.

Exam trap

XK0-006 often tests the assumption that any command with a -h flag produces human-readable output, when in fact -h means different things (or nothing) across tools like vmstat and iostat, leading candidates away from free -h.

How to eliminate wrong answers

Option B is wrong because vmstat does not support a -h flag for human-readable output; vmstat reports virtual memory statistics in raw numbers and is used for paging and CPU activity, not formatted memory summaries. Option C is wrong because cat /proc/meminfo dumps raw kernel memory statistics in kilobytes without human-readable formatting, requiring manual conversion. Option D is wrong because iostat reports CPU and I/O device statistics, not memory or swap usage, and does not provide a human-readable memory summary.

43
Multi-Selectmedium

An administrator needs to identify which processes are consuming the most CPU and memory resources. Which two commands can provide this information? (Choose two.)

Select 2 answers
A.top
B.free -h
C.iostat -x
D.vmstat 1 5
E.ps aux --sort=-%mem
AnswersA, E

top presents a live, self-refreshing process list ordered by CPU consumption by default, also showing per-process memory usage. Its interactive display satisfies the requirement to identify the heaviest CPU and memory consumers in real time.

Why this answer

Option A, top, is correct because it is an interactive process monitor that displays a live, continuously refreshed list of running processes ranked by CPU usage by default, and it also shows per-process memory (RES/%MEM) so the administrator can identify the top CPU and memory consumers in one view. Option E, ps aux --sort=-%mem, is correct because it produces a static snapshot of all processes (a = all users, u = user-oriented format, x = include processes without a controlling terminal) sorted in descending order by memory percentage, which directly reveals the heaviest memory consumers and, with the aux output, their CPU usage as well. Option B, free -h, is not correct because it only reports aggregate system memory and swap usage in human-readable units, not per-process consumption.

Option C, iostat -x, is not correct because it reports extended disk I/O and CPU utilization statistics per device, not which processes are using CPU or memory. Option D, vmstat 1 5, is not correct because it samples system-wide virtual memory, CPU, and I/O statistics every second for five iterations, but it does not attribute resource usage to individual processes.

Exam trap

The key distinction is between system-wide monitoring commands (like `free`, `vmstat`, `iostat`) and per-process commands (like `top`, `ps`). Candidates mistakenly choose `free -h` or `vmstat` thinking they show per-process CPU/memory details.

44
MCQeasy

A user reports that they cannot access a website by domain name but can access it by IP address. Which of the following is the most likely cause?

A.DNS resolution problem
B.Web server is down
C.Firewall blocking port 80
D.Incorrect default gateway
AnswerA

Successful access by IP address proves network routing and the web service function correctly, isolating the failure to name-to-address translation. DNS resolution is therefore the fault, since the client cannot map the domain to the reachable IP.

Why this answer

The user can access the website by IP address but not by domain name, which directly indicates that the system is unable to resolve the domain name to its corresponding IP address. This is a classic symptom of a DNS resolution problem, where the DNS client cannot query a DNS server or the DNS server fails to return the correct A or AAAA record. The fact that the web server is reachable by IP confirms that network connectivity and the web service itself are functioning correctly.

Exam trap

This question tests the distinction between connectivity issues and name resolution issues. The trap is that candidates may confuse a DNS failure with a web server or firewall problem, even though the ability to reach the server by IP clearly rules out those causes.

How to eliminate wrong answers

Option B is wrong because if the web server were down, the website would be inaccessible by both domain name and IP address, not just by domain name. Option C is wrong because a firewall blocking port 80 would prevent HTTP traffic regardless of whether the destination is specified by domain name or IP address, so both methods would fail. Option D is wrong because an incorrect default gateway would prevent all traffic destined for external networks, including both domain name resolution and direct IP access, so the user would not be able to access the site by IP address either.

45
MCQmedium

An administrator needs to check the current routing table on a Linux system. Which command should be used?

A.dig -t A
B.ss -r
C.ip neigh
D.ip route
AnswerD

ip route queries the kernel's routing table through the modern iproute2 suite, listing destination networks, gateways and egress interfaces. It replaces the deprecated route command and satisfies the requirement to inspect current routing entries on the system.

Why this answer

The `ip route` command displays the kernel routing table, showing the paths that packets take to reach network destinations. This is the standard tool on modern Linux systems for viewing and manipulating routing entries, replacing the older `route -n` command.

Exam trap

The trap here is that candidates confuse `ip neigh` (which shows ARP entries) with `ip route` (which shows the routing table), as both involve network path information but serve entirely different layers of the network stack.

How to eliminate wrong answers

Option A is wrong because `dig -t A` is a DNS lookup tool that queries for A records, not a routing table viewer. Option B is wrong because `ss -r` is not a valid flag combination; `ss` is used for socket statistics, and the `-r` flag does not exist (the correct flag for resolving hostnames is `-r` in `route`, not `ss`). Option C is wrong because `ip neigh` displays the neighbor table (ARP cache), which maps IP addresses to MAC addresses on the local link, not the routing table.

46
MCQeasy

A technician is troubleshooting a network connectivity issue. They need to trace the path packets take to a remote server and see the round-trip time for each hop. Which command should they use?

A.ping
B.nslookup
C.traceroute
D.nmap
AnswerC

traceroute sends packets with incrementally increasing TTL values, causing each router along the path to return an ICMP Time Exceeded message. This reveals every hop to the remote server plus the round-trip time per hop, exactly matching the diagnostic requirement.

Why this answer

traceroute (or tracepath) shows the path and RTT per hop.

47
MCQmedium

A user cannot access a website, but other websites work. The administrator wants to see the HTTP response headers from the web server. Which command is most appropriate?

A.wget --spider https://example.com
B.curl -I https://example.com
C.curl -v https://example.com
D.telnet example.com 80
AnswerB

The -I flag makes curl issue a HEAD request, returning only the HTTP response headers without the body. This directly satisfies the administrator's goal of inspecting server headers to diagnose why one site fails while others load.

Why this answer

The curl -I command sends a HEAD request to the server and displays only the HTTP response headers. This is the most appropriate way to quickly inspect headers like status codes, content-type, and server information without downloading the body. It directly addresses the administrator's need to see response headers.

Exam trap

XK0-006 often tests the difference between curl -I (headers only) and curl -v (verbose with body), or confuses wget --spider with header inspection, but the exam expects knowledge that -I is the precise tool for headers.

How to eliminate wrong answers

Option A is wrong because wget --spider only checks if the URL is accessible (like a link checker) and does not display response headers by default. Option C is wrong because curl -v provides verbose output including headers but also includes connection details and body data, making it less focused for just headers. Option D is wrong because telnet only establishes a raw TCP connection and requires manual HTTP request crafting; it does not automatically fetch or display headers.

48
MCQeasy

A user reports that they are unable to write to a USB drive mounted at /mnt/usb. The administrator checks the mount options and sees that the drive is mounted read-only. Which command should the administrator use to remount the filesystem as read-write without unmounting it?

A.mount -o remount,rw /mnt/usb
B.mount -o rw,remount /dev/sdb1
C.fsck -y /dev/sdb1 && mount -o remount,rw /mnt/usb
D.umount /mnt/usb && mount -o rw /dev/sdb1 /mnt/usb
AnswerA

mount -o remount,rw /mnt/usb remounts the filesystem at /mnt/usb with the read-write option, without unmounting. This is the standard way to change mount options on a live filesystem, assuming the underlying device supports it and there are no errors.

Why this answer

The administrator needs to change the mount options of a mounted filesystem from read-only to read-write without unmounting. The mount command with the remount option allows this. Specifying -o remount,rw along with the mount point performs the remount in place.

This is efficient and avoids disruption to processes using the filesystem.

Exam trap

The trap here is thinking that you must unmount to change mount options, or that specifying the device instead of the mount point is sufficient for remounting.

49
Multi-Selectmedium

A Linux administrator is troubleshooting a server that intermittently loses network connectivity. They suspect duplicate IP address conflicts on the local subnet. Which TWO commands can be used to detect whether another host is using the same IP address as the server? (Choose two.)

Select 2 answers
A.ip neigh show
B.arping -D -I eth0 192.168.1.50
C.nmap -sn 192.168.1.0/24
D.ethtool eth0
E.tcpdump -i eth0 arp
AnswersB, E

`arping -D` sends ARP probes in duplicate address detection mode. If another host replies, a duplicate IP is present. Specifying the interface with `-I eth0` and the target IP checks that address on the local segment. This is a direct and reliable method to detect IP conflicts because ARP operates at layer 2 and will receive a response from any host claiming the same address.

Why this answer

Duplicate IP detection requires either actively probing with ARP, as `arping -D` does, or passively observing ARP traffic for conflicting MAC-to-IP mappings, which `tcpdump -i eth0 arp` provides. Both methods operate at layer 2 where the conflict manifests. Commands that merely list hosts or interface settings cannot reveal two hosts claiming the same address.

Exam trap

The trap here is assuming that a ping sweep or ARP cache listing will reveal an IP conflict, when only active ARP probing or capturing ARP frames can expose two hosts using the same address.

50
MCQeasy

A Linux administrator is troubleshooting a server that has lost network connectivity. The administrator runs `ip a` and sees that the interface `ens33` is in the DOWN state and has no IP address assigned. The administrator wants to bring the interface up and assign it an IP address of 192.168.1.50/24. Which command should the administrator use?

A.ip addr add 192.168.1.50/24 dev ens33
B.ifconfig ens33 192.168.1.50 netmask 255.255.255.0 up
C.ip link set ens33 up && ip addr add 192.168.1.50/24 dev ens33
D.ip route add 192.168.1.0/24 dev ens33
AnswerC

This command sequence first brings the interface `ens33` up using `ip link set ens33 up`, then assigns the IP address with `ip addr add`. This is the correct approach because the interface must be administratively up to pass traffic. The `&&` ensures the second command runs only if the first succeeds, which is good practice.

Why this answer

To restore connectivity, the administrator must both bring the interface up and assign an IP address. The `ip link set ens33 up` command changes the administrative state to UP, and `ip addr add` assigns the address. Combining them ensures the interface is operational with the correct IP, which is the most direct solution.

Exam trap

The trap here is thinking that assigning an IP address automatically brings the interface up; in reality, the link state must be set to UP separately.

51
Multi-Selectmedium

An administrator needs to verify DNS resolution for a web server. Which TWO commands can be used to query DNS A records for a given hostname? (Choose two.)

Select 2 answers
A.traceroute
B.nslookup
C.ping
D.dig
E.curl -I
AnswersB, D

The `nslookup` utility queries DNS servers directly and returns A records mapping a hostname to its IPv4 address, satisfying the requirement to verify DNS resolution for the web server. It supports both interactive and non-interactive modes, letting the administrator specify the target hostname and confirm the resolved address.

Why this answer

Option B (nslookup) is correct because it is a dedicated DNS query tool that, by default, resolves a hostname to its A record (IPv4 address) by querying the configured DNS resolver, and it can also be used interactively to specify record types. Option D (dig) is correct because it is a DNS lookup utility that explicitly queries DNS records; running 'dig hostname A' returns the A record along with authoritative server and query details. Option A (traceroute) is incorrect because it maps the network path to a host using TTL-limited packets, not DNS record queries.

Option C (ping) is incorrect because although it resolves a hostname to an IP via the resolver, it is an ICMP reachability test rather than a DNS query tool and does not let you query specific record types. Option E (curl -I) is incorrect because it sends an HTTP HEAD request to fetch response headers, not a DNS A record query.

Exam trap

The trap is that ping and traceroute appear to 'use DNS' because they resolve hostnames, leading candidates to think they can query A records — but they only perform forward resolution as a side effect, not a queryable DNS lookup.

52
MCQhard

A Linux administrator notices that a server's clock is drifting and NTP synchronization is failing. The administrator runs 'chronyc sources' and sees that all sources are marked with a '?' character. Which command should be run next to diagnose why chronyd cannot reach the NTP servers?

A.chronyc ntpdata
B.chronyc tracking
C.chronyc activity
D.chronyc sourcestats
AnswerA

chronyc ntpdata displays detailed NTP packet information for each configured source, including the source address, mode, stratum, and whether packets are being received. When a source shows '?', it indicates that no valid packets have been received recently. ntpdata will reveal if packets are being sent but not returned, or if there are errors, helping diagnose firewall, routing, or server issues.

Why this answer

The '?' character in chronyc sources means the source is unreachable or has not provided a valid packet. To diagnose why, chronyc ntpdata shows per-source packet details, including whether NTP requests are being sent and responses received. This helps identify network blocks, incorrect server addresses, or firewall rules.

Other chronyc subcommands like tracking, activity, and sourcestats do not provide the packet-level view needed for this specific failure.

Exam trap

The trap here is confusing the '?' state with a simple lack of synchronization, when it actually indicates the source is unreachable and requires packet-level diagnosis.

53
MCQmedium

A system administrator notices that a web server is running but users cannot connect to port 443. Which ss command will show if the server is listening on that port?

A.ss -s
B.ss -tlnp
C.ss -tuln
D.ss -tan
AnswerB

Shows TCP listening sockets with process info.

Why this answer

The ss command with -tlnp shows TCP sockets (-t), in listening state (-l), with numeric ports (-n), and the owning process (-p). That combination directly answers whether anything is bound to TCP 443 and which process holds it. This is the standard diagnostic for a web server that is running but unreachable on its expected port.

Exam trap

The trap is picking a broader flag set like -tuln or -tan that shows sockets but omits either the process owner or the listening-only filter needed to pinpoint port 443.

How to eliminate wrong answers

Option A is wrong because 'ss -s' prints summary statistics of socket usage, not per-socket listening details. Option C is wrong because 'ss -tuln' adds UDP (-u) and omits the process (-p), so it shows listeners but not which process owns port 443, weakening the diagnosis. Option D is wrong because 'ss -tan' shows all TCP sockets in all states without restricting to listeners, producing a noisy list that includes established and time-wait connections.

54
MCQmedium

A system administrator notices that the server is performing poorly. Running 'vmstat 1 5' shows high 'wa' values. Which subsystem is most likely experiencing a bottleneck?

A.Memory
B.Disk I/O
C.Network
D.CPU
AnswerB

The wa column in vmstat reports the percentage of CPU time spent idle while waiting for I/O completion. Persistently high wa values indicate processes blocked on storage operations, so the bottleneck lies in the disk I/O subsystem.

Why this answer

In vmstat output, the 'wa' column reports the percentage of CPU time spent waiting for I/O operations to complete. High 'wa' values indicate that the CPU is idle but blocked waiting on disk (or other block device) I/O, which points directly to a disk I/O bottleneck. This is distinct from high 'us' or 'sy' (user/system CPU) or high 'si'/'so' (swap), which would indicate CPU or memory pressure respectively.

Exam trap

The trap is that candidates see 'wa' and think 'wait' means CPU waiting, so they pick CPU; the exam expects you to know 'wa' is I/O wait, not CPU wait.

How to eliminate wrong answers

Option A is wrong because memory bottlenecks in vmstat show up as high 'si' and 'so' (swap in/out) or a growing 'free'/'buff'/'cache' imbalance, not as high 'wa'. Option C is wrong because network bottlenecks are not directly represented by 'wa'; they would typically be diagnosed with netstat, ss, sar -n DEV, or iftop, and may show up as high system CPU ('sy') from interrupt handling, not I/O wait. Option D is wrong because CPU bottlenecks manifest as high 'us' (user) or 'sy' (system) percentages, or high 'id' being low, not as high 'wa' — 'wa' specifically means the CPU is idle waiting on I/O.

55
Multi-Selecthard

A Linux administrator is troubleshooting a server that has lost network connectivity. They need to verify the current IP configuration and check the default gateway. Which TWO commands can be used to display the IP address and routing table? (Choose two.)

Select 2 answers
A.route -n
B.ip addr show
C.ip route show
D.ifconfig -a
E.netstat -rn
AnswersB, C

ip addr show displays all network interfaces and their assigned IP addresses, including subnet masks. It is the modern replacement for ifconfig and provides detailed information about interface state. In this scenario, it directly shows whether the interface has an IP, which is essential for diagnosing connectivity loss. It does not show the routing table, but it is one of the required commands.

Why this answer

The ip addr show command reveals interface IP addresses, and ip route show displays the routing table including the default gateway. Together they provide the necessary information to diagnose network connectivity loss. These are the modern, recommended tools for network configuration inspection on Linux.

Exam trap

The trap here is selecting deprecated commands like ifconfig or netstat instead of the current iproute2 utilities, or choosing commands that only cover half of the requirement.

56
Multi-Selecthard

A system administrator is investigating a slow website. The web server is responding but pages load slowly. Which THREE commands can help identify network latency or packet loss?

Select 3 answers
A.dig example.com
B.mtr example.com
C.ping -c 10 example.com
D.ss -tlnp
E.traceroute example.com
AnswersB, C, E

mtr combines ping and traceroute, continuously probing each hop between the host and example.com. It reports per-hop latency, jitter and packet loss, pinpointing whether slowness arises on the local network, an intermediate router or the destination itself.

Why this answer

Option B, mtr example.com, is correct because mtr combines ping and traceroute into a continuous, per-hop report showing packet loss percentages and latency (average/best/worst) at each router along the path, which directly exposes where latency or loss is introduced. Option C, ping -c 10 example.com, is correct because it sends 10 ICMP Echo Requests and reports round-trip time statistics plus packet loss percentage to the destination, giving a quick measure of latency and loss to the target host. Option E, traceroute example.com, is correct because it maps the hop-by-hop path to the destination using incrementing TTL values and reports per-hop RTTs, revealing which intermediate hop adds delay or drops packets.

Option A, dig example.com, is not correct here because it only queries DNS records and measures name-resolution behavior, not end-to-end network latency or packet loss. Option D, ss -tlnp, is not correct because it merely lists local listening TCP sockets and their owning processes, providing no path latency or loss measurements.

Exam trap

CompTIA often tests the distinction between `traceroute` (which shows a single snapshot of path latency) and `mtr` (which provides ongoing, aggregated statistics including packet loss per hop), leading candidates to overlook `mtr` as a superior tool for diagnosing intermittent or persistent network issues.

57
MCQeasy

Users report that a web application on a Linux server is unreachable from external clients. From the server itself, curl http://localhost works fine. The administrator wants to confirm whether the service is bound only to the loopback interface. Which command should the administrator run?

A.ss -tlnp
B.nmap -p 80 localhost
C.ip route show
D.tcpdump -i lo port 80
AnswerA

ss -tlnp lists TCP sockets in listening state with their local addresses and owning processes. If the web service shows 127.0.0.1:80 instead of 0.0.0.0:80 or the host address, it is bound only to loopback, explaining why remote clients fail while localhost succeeds.

Why this answer

The symptom pattern, local success plus remote failure, often means the daemon is bound to 127.0.0.1 rather than all interfaces. ss -tlnp displays each listening TCP socket's local address and process, making the bind scope explicit. Routing, loopback scanning, and loopback capture all miss the actual socket configuration.

Exam trap

The trap here is assuming the firewall is at fault when localhost works; a loopback-only bind produces the same symptom without any firewall rule.

58
MCQmedium

An administrator needs to check the kernel ring buffer for hardware error messages after a system crash. Which command should be used?

A.dmesg
B.journalctl -k
C.tail -f /var/log/messages
D.strace -e trace=open
AnswerA

dmesg reads the kernel ring buffer, which retains hardware detection, driver and error messages logged by the kernel. After a crash, this buffer holds the relevant hardware diagnostics, satisfying the requirement to inspect kernel-level error output.

Why this answer

dmesg shows kernel ring buffer messages including hardware errors. journalctl -k shows kernel messages from systemd journal, but dmesg is the direct command for the ring buffer.

59
Multi-Selectmedium

A Linux server is experiencing high CPU usage. Which TWO commands can be used to identify which processes are consuming the most CPU? (Choose two.)

Select 2 answers
A.ps aux --sort=-%cpu
B.top
C.iostat
D.vmstat
E.free
AnswersA, B

`ps aux --sort=-%cpu` lists every process with its CPU percentage, sorted descending by that column, so the heaviest consumers appear first. This directly satisfies the stem's requirement to identify which processes are consuming the most CPU on the Linux server, giving an immediate ranked snapshot without interactive monitoring.

Why this answer

Option A, `ps aux --sort=-%cpu`, is correct because it lists all processes with their CPU utilization and sorts them in descending order by the %CPU column, immediately revealing the top CPU consumers. Option B, `top`, is correct because it provides a real-time, dynamically refreshing view of running processes ranked by CPU usage, allowing an administrator to identify which processes are consuming the most CPU. Option C, `iostat`, is incorrect because it reports CPU and I/O statistics per device rather than per-process CPU consumption.

Option D, `vmstat`, is incorrect because it reports system-wide memory, paging, and CPU summary statistics, not individual process CPU usage. Option E, `free`, is incorrect because it only displays memory and swap usage, providing no per-process CPU information.

60
MCQeasy

Which command displays the current routing table on a Linux system?

A.ip neigh
B.ip addr
C.ip link
D.ip route
AnswerD

The ip route command queries the kernel's routing table via the iproute2 suite, listing destination networks, gateways and interfaces. It satisfies the requirement to display current routes, unlike legacy netstat -r or route, which are deprecated on modern Linux distributions.

Why this answer

ip route shows the routing table. The older route command is deprecated.

61
Multi-Selectmedium

A Linux administrator is troubleshooting a service that fails to start. Which TWO commands can be used to view the last 20 lines of the systemd journal for the sshd unit?

Select 2 answers
A.journalctl -u sshd -n 20
B.journalctl -u sshd | tail -20
C.journalctl -k -n 20
D.journalctl -u sshd -p err
E.journalctl -b -u sshd
AnswersA, B

journalctl's -u flag filters entries to the sshd unit, and -n 20 limits output to the last 20 lines, satisfying both stem constraints in one invocation. This queries the systemd journal directly, showing recent sshd startup failures without piping to another utility.

Why this answer

Option A, `journalctl -u sshd -n 20`, is correct because `-u sshd` filters the journal to the sshd unit and `-n 20` limits the output to the last 20 lines, exactly matching the requirement. Option B, `journalctl -u sshd | tail -20`, is also correct because `journalctl -u sshd` produces the sshd unit's journal entries and piping them to `tail -20` displays only the final 20 lines. Option C, `journalctl -k -n 20`, is wrong because `-k` restricts output to kernel messages rather than the sshd unit.

Option D, `journalctl -u sshd -p err`, is wrong because `-p err` filters by priority level (error and above) instead of returning the last 20 lines. Option E, `journalctl -b -u sshd`, is wrong because `-b` limits output to the current boot but does not restrict the result to the last 20 lines.

62
MCQhard

A server is experiencing intermittent network connectivity issues. The administrator wants to run a continuous test that combines ping and traceroute to monitor the path and packet loss to a target host. Which command should be used?

A.mtr target
B.tcpdump -i any host target
C.ping -f target
D.traceroute -n target
AnswerA

`mtr target` continuously combines ping and traceroute, refreshing hop-by-hop latency and packet-loss statistics in real time. This satisfies the stem's requirement for an ongoing test monitoring both path and loss, unlike one-shot `traceroute` or plain `ping`, which cannot show per-hop loss across the route simultaneously.

Why this answer

The mtr command combines the functionality of ping and traceroute by continuously sending packets to a target and displaying per-hop latency and packet loss, making it ideal for monitoring intermittent network issues over time.

Exam trap

XK0-006 often tests the confusion between one-time diagnostic tools like traceroute and continuous monitoring tools like mtr, or the misconception that ping -f provides path analysis.

How to eliminate wrong answers

Option B is wrong because tcpdump captures packets but does not provide a continuous path analysis or packet loss per hop. Option C is wrong because ping -f floods the target with packets, which can cause network congestion and is not a combined ping/traceroute tool. Option D is wrong because traceroute -n only performs a one-time trace and does not continuously monitor or show packet loss over time.

63
MCQeasy

A Linux administrator needs to view all current IPv4 addresses assigned to network interfaces on a system. Which command should be used?

A.ip link show
B.ifconfig -a
C.hostname -I
D.ip addr
AnswerD

`ip addr` queries the kernel's netlink interface and lists every network interface with its assigned IPv4 and IPv6 addresses, satisfying the requirement to view all current IPv4 addresses. Unlike `ifconfig`, it is part of the modern iproute2 suite and remains available on current distributions.

Why this answer

The 'ip addr' command displays all IP addresses assigned to network interfaces. 'ifconfig' is deprecated, 'ip link' shows link-layer info, and 'hostname -I' only shows primary IPs.

64
MCQhard

A Linux server is experiencing intermittent network connectivity issues. The administrator suspects that the network interface is dropping packets due to a duplex mismatch. Which command should be used to check the duplex setting and link status of the interface?

A.ifconfig eth0
B.ip link show eth0
C.netstat -i
D.ethtool eth0
AnswerD

The ethtool command queries and controls network driver and hardware settings. Running ethtool eth0 displays the link status, speed, duplex mode, and other low-level parameters. It directly shows whether the interface is running at full or half duplex, which is critical for diagnosing a duplex mismatch that can cause packet loss and intermittent connectivity.

Why this answer

The ethtool command is the standard tool for querying and modifying Ethernet device settings, including duplex and speed. It directly reports the negotiated duplex mode, allowing the administrator to verify if the interface is operating at half duplex when it should be full duplex. Other commands like ifconfig or ip link do not expose duplex information, and netstat only shows statistics, not configuration.

Exam trap

The trap here is assuming that basic interface commands like ifconfig or ip link show duplex settings; they do not, so ethtool is required.

65
MCQmedium

After adding a new static route to a server, an administrator notices that traffic to 10.20.0.0/16 still leaves through the default gateway. The route appears in 'ip route' output but is not used. The administrator confirms the interface is up. Which command should be run to verify that the kernel is selecting the intended route for that destination?

A.ip neigh show
B.ip addr show
C.ip route get 10.20.5.10
D.ss -rn
AnswerC

ip route get performs a route lookup for a specific destination and reports which interface, source address, and gateway the kernel would actually use. This directly answers whether the new static route wins over the default gateway. Unlike listing the routing table, it shows the resolved decision, making it the right verification tool here.

Why this answer

The kernel consults the routing table using longest-prefix match, so a more specific static route should normally beat the default gateway. When behavior disagrees with the table, the fastest way to see the actual decision is a route lookup for a representative address with ip route get. It reports the chosen interface, gateway, and preferred source, exposing whether a conflicting or less-specific entry is winning.

Exam trap

The trap here is inspecting the routing table or interface list when the real question is which route the kernel resolves for a specific destination.

66
MCQmedium

A system administrator is investigating high disk I/O on a server. Which command can provide disk utilization statistics, including average wait time (await) and percentage of CPU time during which I/O requests were issued (%util)?

A.free -h
B.sar -b 1 5
C.iostat -x 1
D.vmstat 1 5
AnswerC

`iostat -x 1` reports extended disk statistics per device, including await (average wait time in milliseconds) and %util (percentage of time the device had I/O in flight), refreshed every second. This directly satisfies the stem's requirement for both metrics, unlike `vmstat` or `top`, which omit per-device await and %util.

Why this answer

The `iostat` command reports disk I/O statistics including await and %util.

67
Multi-Selecthard

A system is running slowly and the administrator suspects a memory leak. Which THREE commands or tools can be used to analyze memory usage and identify processes consuming excessive memory? (Choose three.)

Select 3 answers
A.strace -p PID
B.ps aux --sort=-%mem
C.iostat -x
D.vmstat 1
E.free -h
AnswersB, D, E

`ps aux --sort=-%mem` lists every process with its resident memory percentage, sorted descending, so the heaviest consumer appears first. This directly satisfies the stem's need to identify processes consuming excessive memory, letting the administrator confirm a suspected leak by watching a process's RSS climb over successive samples.

Why this answer

Option B (ps aux --sort=-%mem) is correct because it lists all processes with their memory usage and sorts them in descending order by the %MEM column, directly revealing which processes consume the most memory. Option D (vmstat 1) is correct because it reports virtual memory statistics (swpd, free, buff, cache, si, so) every second, helping detect memory pressure and swapping indicative of a leak. Option E (free -h) is correct because it displays total, used, free, shared, buff/cache, and available memory in human-readable units, giving a quick overview of overall memory consumption.

Option A (strace -p PID) is not appropriate here because strace traces system calls of a single process and does not summarize memory usage across processes. Option C (iostat -x) is incorrect because it reports extended disk I/O statistics, not memory usage.

Exam trap

XK0-006 often tests the distinction between memory and I/O monitoring tools, tempting candidates to choose iostat or strace for memory analysis when they are not appropriate.

68
MCQhard

A technician suspects a process is leaking file descriptors. Which command can be used to list open files associated with a specific PID?

A.top -p PID
B.strace -p PID
C.ltrace -p PID
D.lsof -p PID
AnswerD

lsof lists open files, and the -p flag restricts output to the specified process ID, directly exposing the file descriptors that process holds. This satisfies the stem's constraint of listing open files tied to a specific PID, revealing leaked descriptors such as unclosed sockets or handles.

Why this answer

The lsof (list open files) command with the -p flag filters output to show all open files associated with a specific process ID. Since Linux treats file descriptors as open files (including sockets, pipes, and regular files), lsof -p PID is the canonical tool for diagnosing file descriptor leaks by revealing exactly what a process has open.

Exam trap

The trap here is confusing process-monitoring tools (top) or syscall tracers (strace, ltrace) with file-descriptor inspection tools; candidates must remember that only lsof enumerates open files by PID.

How to eliminate wrong answers

Option A is wrong because top -p PID only displays real-time CPU, memory, and process statistics for that PID — it does not enumerate open file descriptors. Option B is wrong because strace -p PID traces system calls made by the process, which shows syscall activity but does not produce a list of currently open file descriptors. Option C is wrong because ltrace -p PID traces library calls (such as libc function invocations) and likewise does not enumerate open files.

69
MCQhard

A Linux server intermittently loses its default route after several hours of uptime, and users cannot reach external networks until the route is manually restored. The administrator suspects that a second default route is being installed and removed by a network management daemon. Which command should the administrator use to monitor route changes in real time?

A.ip route show table main
B.ip -s link show
C.journalctl -u NetworkManager --since "1 hour ago"
D.ip monitor route
AnswerD

ip monitor route subscribes to kernel routing notifications and prints every route addition, deletion, or change as it happens. This directly captures the intermittent install and removal events the administrator suspects, including which prefix and gateway are affected, without polling or restarting services.

Why this answer

Intermittent route loss requires observing events as they happen rather than sampling the table. ip monitor route taps the kernel's routing netlink multicast group and prints each add, delete, and change with details, so the flapping default route and its timing become visible. A one-time table dump, interface counters, and indirect daemon logs cannot provide that event stream.

Exam trap

The trap here is using ip route show repeatedly and concluding the route is stable because each snapshot happens to look correct between flaps.

70
MCQmedium

A system is experiencing high load average. The administrator runs 'vmstat 1 5' and sees a high 'wa' value. What does this indicate?

A.High disk I/O wait
B.High memory swapping activity
C.High CPU usage by user processes
D.High network I/O
AnswerA

The wa column in vmstat reports the percentage of CPU time spent idle while waiting for I/O operations to complete. A persistently high value therefore indicates processes blocked on disk I/O, identifying storage as the bottleneck causing the elevated load average.

Why this answer

The 'wa' column in vmstat output indicates the percentage of time the CPU is waiting for I/O operations to complete. A high 'wa' value means the CPU is idle because it is blocked waiting for disk I/O, which directly points to high disk I/O wait. This is a classic indicator of a storage bottleneck.

Exam trap

The trap here is that candidates confuse 'wa' with memory swapping or CPU usage, but vmstat columns are distinct: 'wa' is specifically I/O wait, while swapping is shown in 'si' and 'so', and CPU usage in 'us' and 'sy'.

How to eliminate wrong answers

Option B is wrong because high memory swapping activity is indicated by high 'si' (swap in) and 'so' (swap out) columns in vmstat, not the 'wa' column. Option C is wrong because high CPU usage by user processes is shown in the 'us' column, not 'wa'. Option D is wrong because high network I/O is not directly measured by vmstat; it would be diagnosed using tools like netstat or iftop, and 'wa' specifically reflects disk I/O wait, not network.

71
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service unit file is present and enabled, but systemctl status shows 'failed' with exit code 203. Which command should the administrator run to view the most recent log messages specific to this service?

A.dmesg | grep servicename
B.tail -f /var/log/messages
C.systemctl cat servicename.service
D.journalctl -u servicename.service -n 50
AnswerD

journalctl -u filters logs for a specific systemd unit. The -n 50 option shows the last 50 lines. This directly provides the recent log messages for the failing service, which is exactly what is needed. Exit code 203 often indicates an exec failure, and the logs will reveal the exact error.

Why this answer

The administrator should use journalctl -u servicename.service -n 50 to view the most recent log entries for that unit. This command queries the systemd journal, which captures stdout/stderr from the service and systemd's own messages about start failures. It is the most direct way to diagnose why the service failed with exit code 203.

Exam trap

The trap here is assuming that traditional log files like /var/log/messages contain all service logs, when systemd-based systems primarily use the journal.

72
MCQeasy

A Linux administrator needs to check the amount of free disk space on all mounted filesystems in a human-readable format. Which command should be used?

A.lsblk -f
B.df -h
C.du -sh /*
D.fdisk -l
AnswerB

df -h displays disk space usage for all mounted filesystems in human-readable units (e.g., GB, MB). It shows total size, used space, available space, and mount point. This directly answers the need to check free disk space across all mounts in an easily readable format. It is the standard command for this purpose and is available on all Linux distributions.

Why this answer

df -h is the correct command to check free disk space on all mounted filesystems in human-readable format. It reads filesystem statistics and displays total, used, and available space along with mount points. The other commands serve different purposes: du estimates directory usage, lsblk shows block device and filesystem information without usage, and fdisk lists partitions.

Only df directly reports free space per filesystem.

Exam trap

The trap here is confusing du with df; du shows directory usage but not filesystem free space, which is what the scenario requires.

73
MCQmedium

A server running RHEL 8 has intermittent network connectivity. The administrator wants to view the current DNS resolver configuration. Which file should be examined?

A./etc/sysconfig/network-scripts/ifcfg-eth0
B./etc/nsswitch.conf
C./etc/resolv.conf
D./etc/hosts
AnswerC

/etc/resolv.conf holds the active DNS resolver configuration, listing nameserver entries the system queries. On RHEL 8, NetworkManager or systemd-resolved may rewrite it dynamically, so it reflects the current resolver state rather than static intent. Examining it directly satisfies the administrator's need to view live DNS settings causing intermittent connectivity.

Why this answer

The /etc/resolv.conf file is the standard configuration file that lists the DNS nameservers (via 'nameserver' directives) and search domains used by the resolver. On RHEL 8, even when NetworkManager manages DNS, the effective resolver configuration is written to /etc/resolv.conf (often as a symlink to /run/NetworkManager/resolv.conf). Therefore, examining this file shows the current DNS resolver settings.

Exam trap

The trap here is confusing interface configuration files (like ifcfg-eth0) or name service switch files (nsswitch.conf) with the actual DNS resolver configuration, leading candidates to pick a file that only indirectly affects DNS.

How to eliminate wrong answers

Option A is wrong because /etc/sysconfig/network-scripts/ifcfg-eth0 contains interface configuration (IP address, netmask, gateway, and possibly DNS1/DNS2), but it is not the active resolver configuration file; it only defines what may be applied. Option B is wrong because /etc/nsswitch.conf controls the order of name service databases (e.g., files, dns, nis) but does not contain DNS server addresses or resolver options. Option D is wrong because /etc/hosts provides static hostname-to-IP mappings and is consulted before DNS, but it is not the DNS resolver configuration file.

74
Multi-Selectmedium

A Linux administrator is troubleshooting a server that is running out of disk space. Which TWO commands can be used to identify which directories or files are consuming the most space? (Choose two.)

Select 2 answers
A.iostat -d
B.ls -laR /
C.du -sh /*
D.find / -type f -size +100M -exec ls -lh {} \;
E.df -h
AnswersC, D

The du command estimates file space usage. The -s option summarizes each argument, and -h makes the output human-readable. Running du -sh /* shows the total size of each top-level directory, quickly identifying which directory is using the most space. This is a fast and effective way to pinpoint the largest consumers.

Why this answer

To identify space consumption, du -sh /* summarizes the size of top-level directories, quickly showing which are largest. The find command with -size +100M locates large individual files. Together, they help pinpoint both large directories and files. df only shows filesystem-level usage, ls -laR is too verbose, and iostat measures I/O performance, not space.

Exam trap

The trap here is confusing disk space usage with disk I/O performance, or using df alone which does not show directory-level details.

75
MCQmedium

A system administrator is troubleshooting a service that fails to start. They want to see the recent logs for that specific service unit. Which journalctl command should be used?

A.journalctl -k
B.journalctl -u service_name
C.tail -f /var/log/syslog
D.journalctl -p err
AnswerB

The -u flag filters journalctl output to a single systemd unit, matching the requirement to see logs for one specific service. Without it, journalctl returns the full merged journal, which obscures the failing unit's recent entries.

Why this answer

The `-u` option in `journalctl` filters logs by the systemd unit name, allowing you to view recent logs specifically for a service. This is the correct approach when troubleshooting a service that fails to start, as it isolates the relevant log entries without noise from other system messages.

Exam trap

The trap here is that candidates may confuse `journalctl -u` with other common options like `-k` (kernel) or `-p` (priority), or fall back to legacy syslog commands like `tail -f /var/log/syslog`, which do not directly filter by systemd unit and may miss critical journal-only logs.

How to eliminate wrong answers

Option A is wrong because `journalctl -k` shows kernel messages only, not service-specific logs. Option C is wrong because `tail -f /var/log/syslog` is a traditional syslog command that does not filter by systemd unit and may not capture all journald entries, especially on systems using only journald. Option D is wrong because `journalctl -p err` filters by priority level (error and above), which may omit informational or debug messages that are crucial for diagnosing a startup failure.

Page 1 of 2 · 105 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Troubleshooting questions.