Courseiva

LPIC-1 Shells, Scripting and Data Management Practice Question

A user wants to view the first 10 lines of a log file named /var/log/syslog. Which command should they use?

⚠ Common exam trap

A common mix-up: candidates confuse head and tail, or thinking that a pager like less automatically limits output to the first 10 lines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

head /var/log/syslog

The head command is designed to output the first part of files, with a default of 10 lines. It is the correct choice for viewing the first 10 lines of a log file. The tail command shows the last lines, while cat and less display the entire file or allow interactive viewing without limiting to the first 10 lines. This is a basic file inspection task in Linux.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tail /var/log/syslog

    Why it's wrong here

    The tail command displays the last 10 lines of a file by default, not the first 10. It is often used to monitor log files for recent entries, especially with the -f option to follow updates. However, in this scenario, the user specifically wants the first 10 lines, so tail would show the wrong end of the file. Thus, it does not meet the requirement.

  • ✗

    cat /var/log/syslog | more

    Why it's wrong here

    The cat command concatenates and displays the entire file, and piping to more allows pagination. This would show the file from the beginning, but it displays all lines, not just the first 10. The user would need to manually quit after viewing the first screen. This is less efficient and not the intended command for extracting a specific number of lines from the start.

  • ✓

    head /var/log/syslog

    Why this is correct

    The head command by default displays the first 10 lines of a file. This is exactly what the user needs. It is a simple and efficient way to peek at the beginning of a file without loading the entire file into memory. This command is part of coreutils and is commonly used in shell scripting and daily administration for quickly inspecting file contents.

  • ✗

    less /var/log/syslog

    Why it's wrong here

    The less command is a pager that displays the file starting from the beginning, but it does not limit output to the first 10 lines. It allows scrolling and searching, which is more interactive but not a direct way to get just the first 10 lines. While you could view the beginning, the command itself does not truncate the output. Therefore, it is not the precise tool for this task.

About these practice questions

One of 402 original LPIC-1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official LPI exam blueprint

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.