LPIC-1 Essential System Services and Networking Practice Question
A Linux administrator needs to view the current kernel ring buffer messages to diagnose a hardware issue that occurred during boot. Which command will display these messages?
⚠ Common exam trap
Test-takers frequently confuse the kernel ring buffer with general system logs, leading to commands that may not show all hardware messages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dmesg
The kernel ring buffer stores messages generated by the kernel, including hardware detection and driver initialization. The dmesg command is specifically designed to read and display this buffer. Other commands like journalctl -k or log files may contain overlapping information but are not guaranteed to show the full ring buffer, especially for early boot messages. Therefore, dmesg is the most direct and reliable choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
journalctl -k
Why it's wrong here
journalctl -k displays kernel messages from the systemd journal, which may include the same information as dmesg but only if the journal has captured kernel messages. On systems without persistent journal storage or where kernel logging to journal is disabled, this command might not show all boot-time hardware messages. For direct access to the kernel ring buffer, dmesg is more reliable and universally available.
- ✗
tail -f /var/log/syslog
Why it's wrong here
The /var/log/syslog file contains system logs, including some kernel messages if the syslog daemon is configured to capture them, but it is not the kernel ring buffer. It may not include all boot-time hardware messages, and the tail -f command only shows new entries as they are written. For a complete view of kernel ring buffer messages, dmesg is the correct command.
- ✓
dmesg
Why this is correct
The dmesg command displays the kernel ring buffer, which contains messages from the kernel, including hardware detection, driver loading, and boot-time messages. It is the standard tool to view these messages in real time or from the last boot. The administrator can use dmesg to diagnose hardware issues by examining the output for errors or warnings related to devices.
- ✗
cat /var/log/messages
Why it's wrong here
The file /var/log/messages typically contains general system logs, including some kernel messages, but it is not the kernel ring buffer. It may not include all hardware-related messages, especially those emitted early in boot before the logging daemon starts. The kernel ring buffer is a separate in-memory buffer, and dmesg is the dedicated tool to read it. Relying on /var/log/messages could miss critical early hardware errors.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official LPI exam blueprint
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.