LPIC-1 Administrative Tasks Practice Question
A technician needs to inspect a compressed log archive named app.log.gz without modifying it, and wants to view only the first 20 lines. The archive is 40 MB compressed. Which command accomplishes this most efficiently?
⚠ Common exam trap
The trap here is using plain gunzip, which deletes the original archive and fully expands it, instead of the streaming -c form that preserves the file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
gunzip -c app.log.gz | head -n 20
Streaming the decompressed output to standard output with gunzip -c and piping into head reads only as many lines as needed while leaving the archive untouched. This avoids writing a full uncompressed copy and stops work early, which is the efficient and non-destructive way to peek at the start of a compressed log.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tar -xzf app.log.gz -O | head -n 20
Why it's wrong here
tar expects a tar archive, not a gzip-compressed plain log file. Running tar on a plain gzip stream produces an error because there is no tar header, so this command fails outright. The file is a single compressed log, so a gzip-aware viewer is required instead.
- ✗
zcat app.log.gz > app.log; head -n 20 app.log
Why it's wrong here
zcat writes the fully decompressed contents to a new file, consuming additional disk space and requiring the complete archive to be expanded before any lines are read. It also leaves an extra uncompressed copy behind, which is unnecessary and contrary to the goal of inspecting the archive efficiently.
- ✗
gunzip app.log.gz && head -n 20 app.log
Why it's wrong here
Plain gunzip removes the original .gz archive and replaces it with the decompressed file, which modifies the archive that the technician wants to preserve. It also decompresses the entire 40 MB archive to disk before reading any lines, wasting space and time compared with streaming.
- ✓
gunzip -c app.log.gz | head -n 20
Why this is correct
The -c option writes the decompressed stream to standard output without altering the original file, and piping to head reads only the first 20 lines before closing the pipe. This preserves the archive, avoids writing a full decompressed copy to disk, and stops decompression early, making it the most efficient correct approach.
Go deeper
Related to this question
About these practice questions
One of 402 original LPIC-1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official LPI exam blueprint
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.