Courseiva

LPIC-1 Essential System Services and Networking Practice Question

An administrator needs to monitor real-time network bandwidth usage on a Linux server. Which two tools are specifically designed for this purpose? (Choose two.)

⚠ Common exam trap

Many candidates confuse netstat's interface statistics (e.g., -i option) with real-time monitoring, but netstat only provides cumulative byte/packet counts since boot, not live bandwidth rates, making it unsuitable for real-time bandwidth monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nload

B (nload) is correct because it is a command-line tool that displays real-time network traffic and bandwidth usage on a per-interface basis, showing incoming and outgoing data rates with a dynamic graph. E (iftop) is correct because it listens to network traffic on a specified interface and displays a real-time table of bandwidth usage per connection, similar to top for processes. Both tools are specifically designed for monitoring live bandwidth consumption, unlike general networking utilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    netstat

    Why it's wrong here

    netstat lists socket connections, routing tables and interface statistics such as cumulative byte counters, but it does not display real-time bandwidth rates. It is tempting because it reports per-interface traffic totals and active connections, making it the correct choice for inspecting open ports and established sessions rather than live throughput.

  • ✓

    nload

    Why this is correct

    nload is a console bandwidth monitor that graphs inbound and outbound traffic per network interface in real time, refreshing continuously. It satisfies the stem's real-time bandwidth requirement directly, reading interface counters without packet capture, unlike general utilities such as netstat or ss.

  • ✗

    traceroute

    Why it's wrong here

    traceroute maps the hop-by-hop path packets take to a destination and reports per-hop latency, not bandwidth usage. It is tempting because it is a standard network diagnostic that exposes routing loops, asymmetric paths and where latency accumulates, so it would be correct for diagnosing path or reachability problems.

  • ✗

    ping

    Why it's wrong here

    ping measures round-trip latency and packet loss via ICMP echo requests, not throughput or bandwidth consumption, so it cannot report real-time usage. It is tempting because it is a familiar network diagnostic that reveals connectivity and reachability problems, and would be the right tool for troubleshooting whether a host responds.

  • ✓

    iftop

    Why this is correct

    iftop displays real-time bandwidth usage per connection, pairing hosts and showing throughput rates interactively. It satisfies the stem's real-time bandwidth requirement by reading interface traffic directly, unlike packet analysers such as tcpdump that dump payloads rather than summarising live per-flow bandwidth.

About these practice questions

Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.