Courseiva

LPIC-1 Essential System Services and Networking Practice Question

A junior administrator is asked to verify which TCP ports are listening on a Linux server and which processes own them. Which command provides this information directly?

⚠ Common exam trap

The trap here is assuming any netstat or ip command will show listening ports, when only specific flags like -tulpn or ss -tulpn do so.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ss -tulpn

The ss command with -tulpn is the standard tool on modern Linux to list listening TCP and UDP sockets, show numeric addresses, and map them to owning processes. Netstat -r shows routes, ip link show displays interface state, and lsof -i :22 is limited to a single port. Only ss -tulpn provides a comprehensive view of all listening ports and their processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    netstat -r

    Why it's wrong here

    netstat -r displays the kernel routing table, not listening sockets. While netstat can show listening ports with -tulpn, the -r option specifically prints routes. This command would show default gateways and network destinations, which is unrelated to the task of identifying listening ports and their processes.

  • ✗

    lsof -i :22

    Why it's wrong here

    lsof -i :22 lists processes using port 22 only. It is useful for a single port but does not enumerate all listening ports across the system. To see every listening port, lsof -i -P -n would be needed, and even then it may not clearly separate listening from established sockets without additional filtering.

  • ✗

    ip link show

    Why it's wrong here

    ip link show lists network interfaces and their link-layer status (e.g., MTU, MAC address, up/down state). It does not report listening TCP or UDP ports or the processes bound to them. The administrator would see interface details but no socket information, so this command fails the requirement.

  • ✓

    ss -tulpn

    Why this is correct

    ss is the modern replacement for netstat. The flags -t (TCP), -u (UDP), -l (listening), -p (processes), and -n (numeric) together show all listening TCP and UDP sockets with numeric ports and the associated process. This directly answers which ports are open and which programs own them.

About these practice questions

Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official LPI exam blueprint

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.