Courseiva
User and Group Management →mediumMultiple Select

LFCS w Practice Question

Which THREE commands can be used to list all users currently logged into the system?

⚠ Common exam trap

Candidates often confuse `last` (which shows historical logins) with `w`, `who`, or `users` (which show current logins). They may also overlook that `users` is a valid command, or mistakenly think `id` provides login status. While `w` and `who` are commonly taught, `users` is also correct and should not be dismissed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

w

The w command (A) is correct because it reads /var/run/utmp and displays every user currently logged in along with their terminal, source host, login time, idle time, and current process. The users command (C) is correct because it prints a space-separated list of the login names of all users currently logged into the system, derived from utmp. The who command (E) is correct because it also reads utmp and lists currently logged-in users with their terminal, login time, and remote host. The last command (B) is not correct here because it reads /var/log/wtmp and shows historical login/logout records, including past sessions, not only users currently logged in. The id command (D) is not correct because it displays the UID, GID, and group memberships of a single specified or current user rather than listing all logged-in users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    w

    Why this is correct

    The `w` command reads `/var/run/utmp` and prints every logged-in user alongside their terminal, source host, login time and current activity, satisfying the requirement to list all users currently logged into the system. It shows the full session table rather than only the invoking user, as `whoami` would.

  • ✗

    last

    Why it's wrong here

    last reads the wtmp login history, showing past and current logins with timestamps, not a live list of users currently logged in. It is tempting because it reports login activity, and it would be correct when auditing historical login records rather than active sessions.

  • ✓

    users

    Why this is correct

    The 'users' command reads utmp and outputs a space-separated list of usernames for every active login session, printing a name once per session. It satisfies the requirement to list all users currently logged into the system.

  • ✗

    id

    Why it's wrong here

    The id command reports the invoking user's own UID, GID and group memberships, not a list of logged-in users. It is tempting because it queries user identity data, and it would be relevant when verifying a single account's credentials rather than enumerating active sessions.

  • ✓

    who

    Why this is correct

    `who` reads the utmp database, which records active login sessions, and prints each logged-in user with their terminal, login time and remote host. This directly satisfies the stem's requirement to list all users currently logged into the system, unlike commands that query account databases rather than live sessions.

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.