Courseiva

LFCS Operation of Running Systems Practice Question

A system administrator wants to view the last 10 lines of the system log file '/var/log/syslog' and continue to watch for new lines as they are appended. Which command should be used?

⚠ Common exam trap

Many exam-takers confuse `tail -n 10` (static view) with `tail -f` (follow mode), or mistakenly think `less` with its Shift+F feature is the default answer, but the question explicitly requires a single command that both shows the last 10 lines and continuously watches for new lines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

tail -n 10 -f /var/log/syslog

The `tail -n 10 -f /var/log/syslog` command first displays the last 10 lines of the file and then uses the `-f` (follow) flag to continuously monitor the file for new appended lines, outputting them in real time. This matches the requirement to both view the last 10 lines and watch for new entries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tail -n 10 /var/log/syslog

    Why it's wrong here

    tail -n 10 prints the last ten lines but exits without following, so newly appended entries never appear. Adding -f would satisfy the watch requirement; plain tail is correct only when a one-off snapshot of a file's end is needed.

  • ✗

    less /var/log/syslog

    Why it's wrong here

    less opens the file for interactive paging and does not follow appended content unless the user presses Shift+F; it also starts at the top rather than the last ten lines. It suits browsing and searching a static file, not live monitoring of a growing log.

  • ✓

    tail -n 10 -f /var/log/syslog

    Why this is correct

    The -n 10 flag prints the final ten lines, and -f keeps the file descriptor open, streaming appended lines to standard output as they are written. This combination satisfies both viewing historical entries and live monitoring of /var/log/syslog in one command.

  • ✗

    head -n 10 /var/log/syslog

    Why it's wrong here

    head prints the first ten lines and exits immediately, so it shows neither the tail of the file nor any appended lines. It is the right tool when inspecting the beginning of a file, such as a header row, but the requirement is the end of the log plus continuous following.

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.