LFCS Essential Commands Practice Question
An administrator needs to inspect the first few lines of a very large log file /var/log/syslog without loading the entire file into memory, and also needs to follow new entries as they are appended in real time. Which TWO commands or command combinations satisfy these requirements? (Choose two.)
⚠ Common exam trap
The trap here is treating any pager or search tool as equivalent to a true follow mode, when only tail -f keeps watching for new content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
head -n 20 /var/log/syslog
Viewing the start of a large file efficiently calls for head, which stops after the requested lines. Following appended entries in real time calls for tail -f, which keeps the file open and prints new data. Commands that scan the entire file, such as cat piped to less, grep over the whole file, or wc, do not meet the efficiency or following requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
wc -l /var/log/syslog
Why it's wrong here
wc -l counts lines by reading the entire file from start to finish, so it consumes resources proportional to file size and does not display the first lines or follow new entries. It answers a different question entirely and is not suitable for either requirement described.
- ✓
head -n 20 /var/log/syslog
Why this is correct
head reads only the requested number of lines from the start of the file and then exits, so it does not load the entire log into memory. For a first-lines inspection of a large file, this is efficient and appropriate, satisfying the requirement to view the beginning without processing the whole file.
- ✓
tail -f /var/log/syslog
Why this is correct
The tail -f option opens the file and continuously displays appended lines as they are written, which directly satisfies the real-time following requirement. It does not need to read the entire file into memory and is the standard tool for monitoring growing logs in place.
- ✗
grep -r '' /var/log/syslog
Why it's wrong here
Running grep with an empty pattern over the file still scans every line to match, effectively reading the entire file, which is exactly what the scenario wants to avoid. It also prints matches as they are found rather than following new appends, so it fails both stated requirements.
- ✗
cat /var/log/syslog | less
Why it's wrong here
Piping cat into less reads the entire file through cat before less displays anything, which conflicts with the requirement to avoid loading the whole large file. Although less can page through content, the cat stage defeats the memory-efficiency goal and does not provide real-time following.
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.