Courseiva

CCNA Troubleshooting Questions

30 of 105 questions · Page 2/2 · Troubleshooting topic · Answers revealed

76
MCQeasy

A user reports that they cannot access a web server at 192.168.1.100. The administrator wants to check if the server is reachable and measure round-trip time. Which command is most appropriate?

A.nmap -sn 192.168.1.100
B.traceroute 192.168.1.100
C.ping 192.168.1.100
D.ss -tlnp | grep 192.168.1.100
AnswerC

`ping 192.168.1.100` sends ICMP echo requests to the target and reports whether replies return, satisfying the reachability check, while its summary displays minimum, average and maximum round-trip times in milliseconds, meeting the measurement requirement. It works directly against the IPv4 address without needing name resolution.

Why this answer

The `ping` command sends ICMP Echo Request packets to the target host and waits for ICMP Echo Reply packets, which directly tests reachability and measures round-trip time (RTT). This is the most appropriate tool for the administrator's stated goal of checking if the server is reachable and measuring RTT.

Exam trap

The trap here is that candidates confuse `nmap -sn` (host discovery) with connectivity testing and RTT measurement, or they think `traceroute` measures end-to-end RTT when it actually measures per-hop latency.

How to eliminate wrong answers

Option A is wrong because `nmap -sn` performs a ping sweep (ICMP, TCP SYN to port 443/80, or ARP) to discover live hosts, but it does not provide round-trip time measurements; it only reports whether the host is up. Option B is wrong because `traceroute` shows the path (hops) packets take to reach the destination and measures per-hop latency, not the end-to-end round-trip time to the server itself. Option D is wrong because `ss -tlnp` lists listening TCP sockets on the local system and cannot be used to test reachability to a remote host; it would not even accept an IP address as a filter in that syntax.

77
MCQmedium

A Linux server is experiencing intermittent network connectivity issues. The administrator suspects that packets are being dropped due to a misconfigured firewall rule. Which command should the administrator use to view the current iptables rules and their packet counters?

A.tcpdump -i eth0
B.iptables -F
C.netstat -tuln
D.iptables -L -v -n
AnswerD

The `iptables -L -v -n` command lists all rules in the current chains with verbose output (`-v`) showing packet and byte counters, and `-n` displays IP addresses and ports numerically to avoid DNS lookups. This allows the administrator to see which rules are matching traffic and potentially dropping packets. The counters are essential for identifying if a specific rule is blocking legitimate traffic.

Why this answer

To diagnose firewall-related packet drops, the administrator needs to see the iptables rules along with their match counters. The `iptables -L -v -n` command provides a verbose listing with packet and byte counts, and numeric output. This reveals which rules are being hit and can indicate if a drop rule is matching traffic.

Other commands either modify the firewall or show unrelated information.

Exam trap

The trap here is assuming that network capture tools like tcpdump can show firewall rule counters; they capture packets but do not display iptables rule statistics.

78
Multi-Selectmedium

An administrator notices that a critical application server has become extremely slow, and load average has climbed above 40 on a 4-core system. The administrator wants to identify whether the bottleneck is CPU contention or processes stuck in uninterruptible sleep. (Choose two.)

Select 2 answers
A.Run vmstat 1 and observe the r and b columns.
B.Run df -h and check whether any filesystem is at 100 percent utilization.
C.Run lscpu and verify the number of logical CPUs and their current frequency.
D.Run top and examine the load average fields and the per-process state column.
E.Run free -m and compare the total and used memory values.
AnswersA, D

vmstat reports the number of runnable processes in the r column and processes blocked in uninterruptible sleep in the b column. A persistently high r points to CPU saturation, while a high b points to I/O blocking. Sampling every second reveals which condition dominates.

Why this answer

Load average counts both runnable and uninterruptible-sleep tasks, so a high value alone does not reveal the cause. top exposes per-process state letters alongside load averages, and vmstat's r and b columns quantify runnable versus blocked tasks over time. Memory, CPU topology, and filesystem checks do not separate the two candidate bottlenecks.

Exam trap

The trap here is treating a high load average as proof of CPU exhaustion when blocked-on-I/O tasks inflate it just as much as runnable ones.

79
MCQmedium

An administrator needs to check the kernel ring buffer for hardware error messages from the current boot. Which command displays this information?

A.vmstat -f
B.journalctl -k -b 0
C.cat /var/log/boot.log
D.dmesg
AnswerD

`dmesg` reads the kernel ring buffer directly, exposing hardware and driver messages logged during the current boot. This satisfies the stem's requirement to inspect boot-time hardware errors, unlike journal or log-file tools that may aggregate or filter kernel output.

Why this answer

dmesg displays the kernel ring buffer, which includes hardware-related messages from the current boot.

80
MCQeasy

A user reports that a shell script fails with a 'Permission denied' error when executed, even though the file has the execute bit set for the owner. The administrator runs `ls -l script.sh` and sees `-rwxr-xr-x`. Which command should the administrator use to determine whether the filesystem is mounted with the `noexec` option?

A.lsattr script.sh
B.getfacl script.sh
C.mount | grep noexec
D.stat script.sh
AnswerC

`mount | grep noexec` lists mounted filesystems and filters for the `noexec` mount option. If the filesystem containing the script is mounted with `noexec`, execution is blocked regardless of file permissions. This command directly reveals whether that option is active, explaining the 'Permission denied' error despite the execute bit being set.

Why this answer

A filesystem mounted with `noexec` prohibits execution of binaries and scripts regardless of file permissions. Checking the mount options with `mount | grep noexec` directly confirms whether this is the cause. Other commands inspect file attributes, ACLs, or metadata, none of which can reveal a filesystem-level execution restriction.

Exam trap

The trap here is focusing on file permissions or attributes when the execute bit is already set, overlooking that a `noexec` mount option can block execution independently of file mode.

81
MCQeasy

A user reports that the 'backup.sh' script runs correctly when launched manually but silently does nothing when executed by cron at 02:00. The script relies on 'tar', which is found at /usr/bin/tar. Which action most directly resolves the failure?

A.Move the script into /etc/cron.daily so it inherits the system environment.
B.Set an explicit PATH variable inside the crontab or use absolute paths for commands in the script.
C.Add 'SHELL=/bin/bash' to the crontab to force an interactive login shell.
D.Change the script's permissions to 777 so cron can execute it.
AnswerB

Cron runs jobs with a minimal environment and a PATH that usually excludes /usr/local/bin and sometimes /usr/bin. When the script calls tar by name, the command is not found and the job fails silently unless output is captured. Defining PATH in the crontab or using absolute paths like /usr/bin/tar ensures the commands resolve, matching the manual-versus-cron discrepancy.

Why this answer

Cron jobs run in a minimal environment where PATH typically contains only /usr/bin:/bin, and shell startup files are not sourced. A script that works interactively can fail under cron because commands are resolved against a different PATH or depend on variables set in a profile. Defining PATH explicitly in the crontab, or referencing binaries by absolute path, restores the resolution the script needs.

Capturing stderr to a log also helps reveal such failures.

Exam trap

The trap here is blaming permissions or the shell, when the classic cron failure is a minimal environment missing PATH entries and profile variables.

82
MCQhard

A production web server intermittently stops responding for about 30 seconds at a time. The administrator runs 'vmstat 1' during an incident and observes the 'wa' column consistently above 80 while 'us' and 'sy' remain low. Which conclusion best describes the bottleneck?

A.The kernel is spending excessive time in system calls, indicating a runaway kernel thread.
B.Processes are blocked waiting on I/O, indicating a storage subsystem bottleneck rather than CPU saturation.
C.User-space applications are consuming all available CPU cycles, indicating a runaway process.
D.The system is swapping heavily because physical memory is exhausted, indicating a memory shortfall.
AnswerB

A high wa value in vmstat means CPUs are idle while waiting for I/O operations to complete. Low us and sy confirm the processors are not the constraint. This points to slow or overloaded storage, such as a failing disk, saturated array, or heavy write load, which matches the intermittent stalls and makes storage the correct diagnosis.

Why this answer

In vmstat output the wa column reports the percentage of CPU time spent idle while outstanding I/O requests exist. When wa is very high while us and sy stay low, the processors are not the limiting factor; the storage path is. The intermittent multi-second stalls are consistent with a storage device or array struggling to service requests, so the administrator should investigate disk health, queue depth, and I/O load.

Exam trap

The trap here is reading high wa as a CPU problem, when it actually measures idle time spent waiting for storage to respond.

83
MCQmedium

During boot, a Linux system displays a kernel panic with 'VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.Incorrect time configuration in the BIOS
B.Corrupt initramfs missing a necessary kernel module for the root device
C.The /etc/fstab file has an invalid filesystem type for the root partition
D.A defective network cable
AnswerB

The kernel mounts the root filesystem using drivers supplied by the initramfs. If that image is corrupt or omits the storage or filesystem module, the root device cannot be mounted, producing exactly this unknown-block(0,0) panic during boot.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' occurs when the kernel cannot locate or access the root filesystem device. This typically happens because the initramfs (initial RAM filesystem) is corrupt or missing the kernel module (e.g., storage controller driver like ahci, virtio_blk, or LVM/dm modules) needed to detect and mount the root device. Without that module, the kernel has no way to translate the root= parameter into a usable block device, resulting in unknown-block(0,0).

Exam trap

The trap here is confusing post-boot configuration files like /etc/fstab with pre-boot requirements — candidates often assume any filesystem-related error must come from fstab, but fstab is irrelevant before the root filesystem is mounted.

How to eliminate wrong answers

Option A is wrong because an incorrect BIOS time affects clock accuracy and can cause TLS or logging issues, but it has no bearing on the kernel's ability to mount the root filesystem. Option C is wrong because /etc/fstab is processed by userspace after the root filesystem is already mounted — if the root fs can't be mounted, fstab is never read, so an invalid fstab entry cannot produce this panic. Option D is wrong because a defective network cable would only affect network connectivity; a local root filesystem mount does not depend on the network unless using NFS root, which would produce a different error and is not implied here.

84
Multi-Selectmedium

A system is experiencing boot failures. The administrator wants to view kernel messages from the current boot to diagnose the issue. Which two commands can be used to see these messages? (Choose two.)

Select 2 answers
A.journalctl -k
B.cat /proc/kmsg
C.tail -f /var/log/boot.log
D.dmesg
E.vmstat -f
AnswersA, D

`journalctl -k` reads the kernel ring buffer through systemd's journal, filtering entries to kernel-originated messages only. Because the journal persists per-boot metadata, it can restrict output to the current boot, directly satisfying the requirement to inspect kernel messages from the present boot rather than earlier ones.

Why this answer

Option A, journalctl -k, is correct because the -k (--dmesg) filter restricts systemd-journald output to kernel messages only, and by default journalctl shows the current boot's entries, so it displays kernel messages from the present boot. Option D, dmesg, is correct because it reads the kernel ring buffer, which contains the kernel messages generated during the current boot, making it ideal for diagnosing boot failures. Option B, cat /proc/kmsg, is not a good choice because /proc/kmsg is a blocking, consume-once interface intended for a single reader such as klogd or dmesg; reading it directly can steal messages and it does not cleanly present the current boot log.

Option C, tail -f /var/log/boot.log, is incorrect because boot.log contains service startup output from the init/boot process, not kernel messages, and it may not exist on systemd systems. Option E, vmstat -f, is incorrect because it reports the number of forks since boot, which is unrelated to viewing kernel messages.

Exam trap

The trap here is that candidates confuse `dmesg` with `cat /proc/kmsg` or think `boot.log` contains kernel messages, when in fact `dmesg` and `journalctl -k` are the standard tools for viewing kernel ring buffer output from the current boot.

85
MCQhard

A Linux administrator is troubleshooting a server that randomly drops SSH connections. The administrator suspects a network interface is experiencing errors or discards. Which command should be used to display detailed error and discard statistics for a specific network interface?

A.ip -s link show eth0
B.netstat -i
C.ifconfig eth0
D.ethtool -S eth0
AnswerA

The ip -s link show command displays interface statistics, including RX/TX errors, dropped packets, and overruns. By specifying eth0, the administrator can see detailed counters that indicate whether the interface is experiencing errors or discards, which could explain dropped SSH sessions. This directly addresses the need to inspect error and discard statistics for a specific interface.

Why this answer

The administrator needs error and discard statistics for a specific interface. ip -s link show eth0 provides a standardized, detailed view of RX/TX errors, dropped packets, and overruns. While other tools may show some statistics, ip is the modern, reliable choice and directly meets the requirement.

Exam trap

The trap here is assuming that any interface statistics command will provide the same level of detail, when older or driver-specific tools may lack the necessary error and discard counters.

86
MCQmedium

A Linux server's root filesystem was accidentally filled to 100% capacity by runaway application logs. After the administrator deletes several large log files with rm, df -h still reports the filesystem at 100% usage. Which command should the administrator use to identify the process that is holding these deleted files open?

A.df -i
B.fuser -m /
C.du -sh /var/log
D.lsof +L1
AnswerD

lsof +L1 lists all open files that have a link count less than 1, which indicates deleted files still held open by a process. This directly identifies the process preventing space from being reclaimed, allowing the administrator to restart or kill it to free the space. It is the precise tool for this scenario.

Why this answer

The correct tool is lsof +L1, which specifically lists open files with a link count less than one, indicating deleted files still held open by a process. In this scenario, the deleted log files are still consuming disk space because a process has them open. Identifying and restarting that process will release the space, resolving the 100% usage.

Exam trap

The trap here is assuming that deleting a file immediately frees disk space, when in fact the space remains allocated until all file descriptors referencing it are closed.

87
MCQeasy

A Linux administrator is troubleshooting a service that fails to start. They want to view the most recent log entries for that service using systemd's journal. Which command should they use?

A.dmesg | grep servicename
B.systemctl status servicename
C.journalctl -u servicename
D.tail -f /var/log/messages
AnswerC

journalctl -u filters the journal by the specified systemd unit, showing all log entries for that service. This is the most direct way to see why the service failed. It includes messages from the service's startup, errors, and dependencies, making it ideal for troubleshooting a failed start.

Why this answer

The journalctl -u command filters the systemd journal by unit, providing all log messages for that service. This is the correct tool to diagnose why a service fails to start, as it captures the service's standard output, error messages, and systemd's own messages about the unit.

Exam trap

The trap here is confusing systemctl status, which gives a summary, with journalctl -u, which provides the full log history for the service.

88
MCQmedium

A Linux server has a single disk /dev/sda with LVM. The root logical volume is nearly full and the administrator adds a new disk /dev/sdb to extend it. After creating a physical volume on /dev/sdb and adding it to the volume group, which command should be used to extend the root logical volume and its filesystem in one step?

A.vgextend vg0 /dev/sdb && lvcreate -l +100%FREE -n root vg0
B.lvresize -L +10G /dev/vg0/root && resize2fs /dev/vg0/root
C.pvresize /dev/sdb && lvextend -L +10G /dev/vg0/root
D.lvextend -r -l +100%FREE /dev/vg0/root
AnswerD

The -r (or --resizefs) option to lvextend resizes the underlying filesystem together with the logical volume, so the root LV and its filesystem are extended in a single command. Using -l +100%FREE allocates all remaining free extents in the volume group. This is the correct and efficient way to grow the LV and filesystem without a separate resize2fs or xfs_growfs step.

Why this answer

Extending an LVM logical volume and its filesystem in one step is done with lvextend -r (or --resizefs). The -r flag automatically calls the appropriate filesystem resize tool (resize2fs for ext4, xfs_growfs for XFS) after growing the LV. Using -l +100%FREE allocates all remaining extents in the volume group.

This avoids a separate manual resize step and works for both ext4 and XFS, making it the most reliable choice.

Exam trap

The trap here is assuming that lvextend always resizes the filesystem automatically, when in fact the -r option is required to do so.

89
MCQmedium

A technician wants to check the disk I/O statistics, focusing on the average I/O wait time and utilization percentage. Which command provides this information?

A.sar -b
B.vmstat -d
C.free -h
D.iostat -x
AnswerD

`iostat -x` reports extended disk statistics, including average I/O wait time (await) and device utilisation percentage (%util), satisfying the stem's focus on both metrics. Plain `iostat` omits the extended columns, so the `-x` flag is what exposes per-device await and %util figures.

Why this answer

The iostat -x command displays extended disk I/O statistics, including per-device metrics such as average wait time (await), utilization percentage (%util), and queue sizes. The -x flag is specifically what surfaces these extended columns, making it the correct tool for analyzing I/O wait and utilization. sar -b reports overall block device activity but not per-device extended metrics like await and %util.

Exam trap

XK0-006 often tests the distinction between sar -b (aggregate block activity) and iostat -x (per-device extended metrics), so candidates who only remember 'sar does system activity' pick the wrong tool.

How to eliminate wrong answers

Option A is wrong because sar -b reports aggregate block I/O activity (tps, rtps, wtps, bread/s, bwrtn/s) but does not provide per-device average wait time or utilization percentage. Option B is wrong because vmstat -d shows disk statistics such as reads, writes, and I/O counts per device, but does not report average wait time or utilization percentage. Option C is wrong because free -h only displays memory and swap usage, not disk I/O statistics at all.

90
MCQmedium

A Linux administrator notices that a production server's root filesystem is 100% full, but du reports only 40 GB used on a 100 GB partition. Which command should the administrator use to identify deleted files still held open by running processes?

A.fuser -mv /
B.df -i
C.lsof +L1
D.find / -size +1G -exec ls -l {} \;
AnswerC

lsof +L1 lists all open files whose link count is less than 1, which indicates deleted files still held open by processes. This is exactly the situation where disk space is consumed but du cannot see it because the directory entry is gone. The +L1 filter is specifically designed to find these orphaned inodes, allowing the administrator to identify and restart the offending process.

Why this answer

The discrepancy between df and du indicates deleted files still held open by processes. lsof +L1 specifically lists open files with a link count of zero, which are deleted files still consuming disk space. This allows the administrator to identify the process holding the file and restart it to release the space.

Exam trap

The trap here is assuming that df and du should always match, but deleted files held open by processes cause df to show more usage than du reports.

91
MCQmedium

A Linux server's /var/log partition is 100% full and rsyslogd has stopped writing logs. The administrator needs to find which directories under /var/log consume the most space without deleting anything. Which command should the administrator run?

A.ls -laR /var/log | less
B.du -sh /var/log/* | sort -rh | head -n 10
C.df -h /var/log
D.find /var/log -type f -size +100M -delete
AnswerB

This command summarizes the disk usage of each immediate item under /var/log in human-readable form, sorts them in descending order, and shows the top ten. It identifies the largest directories or files without modifying anything, which directly addresses the need to locate space consumers on the full partition.

Why this answer

To find what is filling a filesystem, aggregate usage per directory and sort by size. du -sh with a glob gives one line per item under /var/log, and sort -rh orders them largest first, so the top offenders are immediately visible. df only shows the filesystem total, find -delete destroys data, and recursive ls provides no aggregation.

Exam trap

The trap here is reaching for df, which confirms the partition is full but cannot identify which subdirectory or file is consuming the space.

92
MCQmedium

A system is experiencing high memory usage. The administrator wants to see a brief summary of memory usage in human-readable format, including buffers and cache. Which command is most appropriate?

A.free -h
B.iostat -m
C.cat /proc/meminfo
D.vmstat -s
AnswerA

`free -h` reads `/proc/meminfo` and prints a concise table of total, used, free, shared, buff/cache and available memory, with the `-h` flag scaling values into human-readable units such as MiB and GiB. This satisfies the stem's requirement for a brief summary that explicitly includes buffers and cache.

Why this answer

free -h is correct because it prints a concise summary of total, used, free, shared, buff/cache, and available memory in human-readable units (MiB/GiB), directly satisfying the requirement to include buffers and cache. The -h flag converts raw kilobytes into readable values, making it the most appropriate single command for a quick memory overview.

Exam trap

The trap here is confusing memory tools with I/O tools: candidates see 'human-readable' and 'buffers and cache' and may pick /proc/meminfo or vmstat -s, but only free -h provides the brief, formatted summary the question demands.

How to eliminate wrong answers

Option B is wrong because iostat -m reports CPU utilization and disk I/O statistics in megabytes per second, not memory usage. Option C is wrong because cat /proc/meminfo dumps dozens of raw kernel counters in kilobytes with no human-readable formatting and no summary, requiring manual interpretation. Option D is wrong because vmstat -s prints a long list of memory-related event counters and statistics rather than a brief human-readable summary with buffers and cache.

93
MCQmedium

A Linux server's root filesystem is filling rapidly. The administrator suspects a process is writing to a deleted file that still holds space. They want to identify which running process has an open file descriptor to a deleted file. Which command should they use?

A.vmstat 1 5
B.ps aux --sort=-%mem
C.lsof +L1
D.df -i /
AnswerC

The lsof +L1 option lists open files with a link count less than one, which identifies deleted files still held open by a process. This directly reveals processes writing to unlinked files that continue to consume disk space. The output shows the PID, command, and file path with a (deleted) marker, giving the administrator exactly the information needed to restart or kill the offending process and reclaim space.

Why this answer

When a process holds a deleted file open, the inode and its blocks remain allocated until the process closes or exits, so the space does not return to the filesystem. The lsof command with +L1 filters open files whose link count is below one, precisely matching deleted-but-open files. It outputs the responsible PID and command, enabling the administrator to restart the process and reclaim the space.

Exam trap

The trap here is assuming that deleting a file immediately frees disk space, when an open file descriptor keeps the inode and blocks allocated until the process releases them.

94
MCQmedium

A Linux server's root filesystem was extended with LVM, but after a reboot users report that only the original capacity is available again. Running 'df -h' shows the mount smaller than the logical volume, and 'lvextend' completed successfully before the reboot. Which command should the administrator run to make the filesystem use the additional space on an XFS root volume?

A.resize2fs /dev/mapper/vg0-root
B.xfs_growfs /
C.parted /dev/sda resizepart 2 100%
D.vgchange -ay vg0
AnswerB

xfs_growfs expands an XFS filesystem online to fill its underlying block device. Because the logical volume was already enlarged with lvextend, running xfs_growfs against the mount point '/' resizes the filesystem to consume the new extents. This is the correct tool for XFS, which cannot be grown with resize2fs, and it works while the root filesystem is mounted.

Why this answer

XFS filesystems must be grown with xfs_growfs rather than resize2fs, and the operation can be performed online on a mounted root filesystem. Since lvextend already expanded the logical volume, the remaining step is to tell XFS to claim the new space by pointing xfs_growfs at the mount point. Without this step the filesystem keeps its original size even though the block device is larger.

Exam trap

The trap here is assuming that any Linux filesystem can be enlarged with resize2fs, when that utility is limited to the ext family and silently fails on XFS.

95
MCQhard

A server running RHEL 8 fails to boot with a 'Dependency failed for /data' error. The /data filesystem is an ext4 partition on /dev/sdb1. Which sequence of steps should be taken to repair the filesystem?

A.Use 'xfs_repair /dev/sdb1' since it's ext4
B.Run 'fsck.ext4 -f /dev/sdb1' from the running system
C.Remount the filesystem as read-only and run fsck
D.Boot into rescue mode, run 'umount /dev/sdb1', then 'fsck.ext4 -f /dev/sdb1'
AnswerD

Rescue mode boots a minimal environment where /data stays unmounted, allowing 'umount /dev/sdb1' to ensure no active references remain before 'fsck.ext4 -f' forces a full check and repair of the ext4 partition, satisfying the need to fix the dependency failure safely.

Why this answer

To repair an ext4 filesystem that failed to mount at boot, you must boot into rescue mode (or single-user), ensure the filesystem is unmounted, then run 'fsck.ext4 -f /dev/sdb1' to force a check and repair. fsck must never run on a mounted read-write filesystem, and rescue mode gives you a clean environment where /data is not mounted. This is the standard RHEL recovery procedure.

Exam trap

XK0-006 often tests the rule that fsck must run on an unmounted filesystem — candidates pick 'run fsck from the running system' or 'remount read-only' not realizing fsck needs full unmount and that rescue mode is required.

How to eliminate wrong answers

Option A is wrong because xfs_repair is for XFS filesystems, not ext4 — running it on ext4 will fail or corrupt data. Option B is wrong because running fsck.ext4 on a mounted filesystem (especially read-write) can cause severe corruption; the running system has /data mounted. Option C is wrong because remounting read-only and running fsck is not sufficient — fsck requires the filesystem to be fully unmounted, not just read-only, and the boot failure means it may not even be mounted.

96
MCQmedium

An administrator is troubleshooting a DNS issue and needs to query the authoritative name servers for example.com. Which dig command should be used?

A.dig example.com MX
B.dig example.com NS
C.dig example.com A
D.dig example.com ANY
AnswerB

The NS record type queries the zone's authoritative name servers, so dig example.com NS returns exactly the delegation data required. Other record types such as A or MX would resolve addresses or mail routing instead, failing the stated troubleshooting goal.

Why this answer

The NS (Name Server) record type identifies the authoritative name servers for a domain. Running 'dig example.com NS' queries those NS records directly, showing which servers are authoritative for example.com. This is the correct query to enumerate authoritative name servers.

Exam trap

The trap is confusing record types — candidates may pick ANY thinking it returns everything, but ANY is unreliable and not the targeted way to query authoritative name servers.

How to eliminate wrong answers

Option A is wrong because 'dig example.com MX' returns mail exchange records, which identify mail servers, not authoritative name servers. Option C is wrong because 'dig example.com A' returns the IPv4 address record for the domain apex, not the NS records. Option D is wrong because 'dig example.com ANY' requests all record types, which is unreliable — many DNS servers (including many modern resolvers) refuse or truncate ANY queries per RFC 8482, and the output is not focused on NS records.

97
Multi-Selectmedium

A system administrator needs to collect performance data over time to analyze CPU and memory usage trends. Which THREE of the following commands can be used to gather historical performance data? (Choose THREE.)

Select 3 answers
A.iostat
B.uptime
C.free
D.sar
E.vmstat
AnswersA, D, E

iostat reports CPU utilisation and disk I/O statistics, and with interval arguments it samples repeatedly, building a historical record of CPU trends. It writes to stdout, so redirecting output to a file captures the data over time.

Why this answer

Option A, iostat, is correct because it reports CPU utilization and disk I/O statistics and can be run repeatedly (e.g., iostat 5) or logged over time to reveal performance trends. Option D, sar, is correct because the System Activity Reporter collects and stores historical performance data via the sadc collector and sysstat service, allowing retrieval of past CPU and memory statistics with commands like sar -u or sar -r. Option E, vmstat, is correct because it samples CPU, memory, paging, and I/O statistics at intervals (e.g., vmstat 5) and its output can be captured over time for trend analysis.

Option B, uptime, is not correct because it only shows a single snapshot of load average and uptime, not historical performance data. Option C, free, is not correct because it displays a one-time snapshot of current memory usage rather than collecting data over time.

Exam trap

XK0-006 often tests the distinction between real-time monitoring tools (like uptime and free) and tools that can provide historical data (like sar and iostat), so candidates may incorrectly include free or uptime.

98
MCQhard

A Linux administrator is troubleshooting a server that becomes unresponsive under load. They want to capture a live, per-second view of CPU usage broken down by individual processor cores, along with load averages. Which command should they use?

A.iostat -x 1
B.top -b -n 1
C.mpstat -P ALL 1
D.free -m
AnswerC

mpstat from the sysstat package reports per-processor statistics. The -P ALL option shows every core, and the interval argument refreshes output each second. It includes CPU utilization percentages and, in recent versions, load averages, making it ideal for observing whether a single core is saturated while others idle. This granularity helps identify unbalanced or single-threaded load causing unresponsiveness.

Why this answer

The mpstat command with -P ALL and an interval argument produces recurring snapshots showing each processor core's utilization, which reveals whether load is spread evenly or concentrated on one core. This per-core visibility is critical when a single-threaded process saturates one CPU while others remain idle, a common cause of apparent unresponsiveness under load. Other tools lack this combination of per-core detail and live refresh.

Exam trap

The trap here is selecting top for CPU analysis, but a batch single-iteration top neither refreshes per second nor shows per-core breakdown, which is what the scenario requires.

99
MCQmedium

A Linux administrator is investigating why a user cannot log in via SSH. The SSH service is running, and the network is reachable. The administrator suspects that the user's account is locked or expired. Which command should they use to check the account status and expiration details for the user 'jdoe'?

A.passwd -S jdoe
B.chage -l jdoe
C.usermod -L jdoe
D.id jdoe
AnswerB

chage -l lists account aging information, including password expiration, account expiration, and last password change. It directly shows if the account has expired or is locked due to password aging. This is the correct tool to verify if the user's account is expired or locked, which would prevent SSH login even if the service is running.

Why this answer

The chage -l command displays detailed account aging information, including expiration dates for the password and the account itself. In this scenario, it would reveal if the account is expired or if the password has expired, which are common reasons for SSH login failure despite the service running. This makes it the correct diagnostic tool.

Exam trap

The trap here is confusing password status (passwd -S) with full account aging information (chage -l), or mistakenly using a modification command like usermod -L instead of a query.

100
MCQhard

A Linux administrator is diagnosing a system that occasionally hangs during boot. The administrator suspects a hardware issue. Which command will display kernel ring buffer messages, including hardware detection and driver errors, from the current boot?

A.journalctl -b -p err
B.lsmod
C.dmesg
D.cat /var/log/boot.log
AnswerC

dmesg prints the kernel ring buffer, which contains messages about hardware detection, driver loading, and kernel events. These messages are generated during boot and runtime. It is the primary tool for viewing kernel-level diagnostics, making it ideal for identifying hardware issues causing boot hangs.

Why this answer

The dmesg command displays the kernel ring buffer, which contains low-level messages about hardware, drivers, and kernel events. These messages are generated during boot and can reveal hardware detection failures, driver errors, or other kernel issues that cause hangs. It is the most direct tool for this purpose.

Exam trap

The trap here is confusing general system logs with the kernel ring buffer, or assuming that a list of loaded modules provides diagnostic messages.

101
MCQmedium

A system is experiencing high disk I/O wait. Which command can provide disk I/O statistics such as requests per second and average wait time?

A.sar -u 1 5
B.iostat -x 1
C.free -h
D.vmstat 1 5
AnswerB

The -x flag extends iostat output with per-device metrics including requests per second, average queue size and average wait time, while the 1 sets a one-second sampling interval. This directly satisfies the requirement for disk I/O statistics during high wait.

Why this answer

The iostat -x 1 command provides extended disk I/O statistics, including requests per second (r/s, w/s), average wait time (await), and utilization (%util), refreshed every second. This directly answers the need for per-device I/O performance data during high I/O wait.

Exam trap

XK0-006 often tests the difference between CPU-focused tools (sar -u, vmstat) and disk-focused tools (iostat -x) — candidates see 'iowait' in sar or vmstat output and assume those tools provide disk-level detail, which they do not.

How to eliminate wrong answers

Option A is wrong because sar -u 1 5 reports CPU utilization statistics (user, system, idle, iowait) every second for five intervals — it shows iowait but not per-disk request rates or wait times. Option C is wrong because free -h displays memory and swap usage, which is unrelated to disk I/O statistics. Option D is wrong because vmstat 1 5 reports virtual memory, process, CPU, and some block I/O summary statistics, but it does not provide per-device requests per second or average wait time like iostat -x does.

102
MCQeasy

A Linux administrator notices that the /home filesystem is full. They want to identify which top-level directories under /home are consuming the most disk space. Which command should they run?

A.ls -lR /home
B.du -sh /home/*
C.df -h /home
D.fdisk -l /dev/sda
AnswerB

The du command estimates file space usage. With -s it summarizes each argument, and -h makes the output human-readable. Running du -sh /home/* expands to each top-level directory and file under /home, giving a per-item total. This directly answers which directories consume the most space without descending into every file, making it the appropriate first step for this scenario.

Why this answer

To find which directories under /home are using the most space, the administrator needs aggregated per-directory sizes. The du command with -s and -h summarizes each top-level directory in human-readable units, directly identifying the largest consumers. Filesystem-level tools like df only confirm fullness, while recursive file listings require manual aggregation and partition tools are unrelated to in-filesystem usage.

Exam trap

The trap here is confusing filesystem-level capacity reporting with per-directory usage accounting, leading to choosing df when the question asks which directories are consuming space.

103
MCQhard

A Linux server's clock drifts by several minutes each day. The administrator runs `timedatectl` and sees that NTP synchronization is enabled but the system clock is not synchronized. The server can reach the internet, and `chronyd` is running. Which command should the administrator use to verify which NTP sources are currently reachable and their stratum levels?

A.systemctl status chronyd
B.timedatectl show-timesync
C.ntpq -p
D.chronyc sources -v
AnswerD

`chronyc sources -v` queries the running chronyd daemon and lists configured time sources with their state, stratum, and reachability. The verbose flag adds details such as mode, poll interval, and last sample statistics. This directly shows whether the configured NTP servers are reachable and at what stratum, allowing the administrator to diagnose why synchronization is not occurring despite chronyd running.

Why this answer

With chronyd running, the correct tool to inspect configured time sources, their reachability, and stratum is `chronyc sources -v`. It queries the daemon directly and provides verbose per-source details, enabling the administrator to identify unreachable or high-stratum servers. Other commands target different NTP implementations or only report service status without source-level diagnostics.

Exam trap

The trap here is using `ntpq -p`, which is the query tool for ntpd, on a system that runs chronyd, where `chronyc` is the correct client and the two are not interchangeable.

104
MCQmedium

A Linux engineer is investigating high disk I/O on a server. Which command provides disk I/O statistics including %util, await, r/s, and w/s?

A.iostat -x 1
B.sar -b
C.vmstat 1 5
D.free -h
AnswerA

The -x flag extends iostat's report with per-device statistics, including %util (device busy percentage), await (average I/O wait), and r/s and w/s throughput. The 1 argument refreshes every second, exposing the sustained disk I/O pattern the engineer needs to diagnose.

Why this answer

iostat reports CPU and disk I/O statistics, with columns like %util, await, r/s, and w/s.

105
MCQmedium

A Linux administrator receives reports that a database server becomes unresponsive every day around 02:00. Reviewing logs, the administrator notices repeated messages about 'blocked for more than 120 seconds' and high I/O wait. Which command should be used to identify which process is generating the most disk I/O during this period?

A.iotop -o -d 5
B.iostat -x 5
C.vmstat 5
D.sar -d 5 3
AnswerA

iotop displays per-process I/O usage, and the -o option shows only processes actively performing I/O. With -d 5, it refreshes every five seconds, allowing the administrator to identify the process generating heavy disk activity during the 02:00 window. This directly addresses the need to attribute I/O to a specific process.

Why this answer

The administrator must attribute heavy disk I/O to a specific process. iotop is designed for per-process I/O monitoring and the -o flag filters out idle processes, making it ideal for identifying the culprit during the nightly issue. Other tools show device-level or system-wide I/O but cannot tie activity to a process.

Exam trap

The trap here is assuming that any I/O monitoring tool will identify the responsible process, when many only report device-level or system-wide statistics.

← PreviousPage 2 of 2 · 105 questions total

Ready to test yourself?

Try a timed practice session using only Troubleshooting questions.