LFCS Essential Commands Practice Question
A system administrator notices that '/var/log/syslog' has grown very large and is consuming significant disk space. The administrator wants to identify the largest log files in the '/var/log' directory hierarchy. Which command should the administrator use?
⚠ Common exam trap
Candidates often choose `ls -lhS /var/log` (option D) because it sorts by size, but they overlook that it does not recurse into subdirectories, missing large files in subfolders like `/var/log/apache2/` or `/var/log/journal/`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
du -ah /var/log | sort -hr | head -10
`du -ah /var/log` calculates the disk usage of all files and directories in `/var/log` in human-readable format, then `sort -hr` sorts them by size in descending order, and `head -10` shows the top 10 largest entries. This directly identifies the largest log files in the hierarchy, which is exactly what the administrator needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
find /var/log -size +100M -exec ls -lh {} \;
Why it's wrong here
find with -size +100M matches files exceeding a fixed 100 MB threshold, so it misses the actual largest files if none reach that size and ignores relative ranking. It is tempting as a size filter, and would be correct if the requirement were to list files above a known limit.
- ✓
du -ah /var/log | sort -hr | head -10
Why this is correct
`du -ah` reports apparent sizes for every file and directory under /var/log, then `sort -hr` orders them largest-first by human-readable size and `head -10` shows the top ten. This directly satisfies the goal of identifying the largest log files within the hierarchy.
- ✗
df -h /var/log
Why it's wrong here
df reports filesystem-level space usage, not individual file sizes, so it cannot rank the largest logs within /var/log. It is tempting because df -h is the standard tool for investigating a full disk, and would be correct if the administrator needed to know which mounted filesystem was running out of space.
- ✗
ls -lhS /var/log
Why it's wrong here
ls -lhS sorts only the immediate directory entries and does not recurse, so files nested in subdirectories such as /var/log/nginx are missed. It is tempting because -S orders by size and -h gives human-readable output, making it correct when the largest files all sit directly in one directory.
Go deeper
Related to this question
About these practice questions
This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.