Courseiva
Essential Tools →mediumMultiple Choice

EX200 Essential Tools Practice Question

A system administrator needs to find all regular files larger than 10MB in /var/log. Which find command should they use?

⚠ Common exam trap

Red Hat often tests the `+` and `-` prefix syntax for `-size`, and the trap here is that candidates confuse `-size +10M` with `-size 10M` or `-size -10M`, or they mistakenly use `-type d` instead of `-type f` when the question specifies regular files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

find /var/log -type f -size +10M

It uses `-type f` to select only regular files and `-size +10M` to match files larger than 10 megabytes. The `+` prefix in the `-size` test means 'greater than', which is the correct syntax for finding files exceeding a given size.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    find /var/log -type f -size -10M

    Why it's wrong here

    The leading hyphen in `-size -10M` tells find to match files smaller than 10 MiB, not larger ones. Because the size comparison is inverted, this command returns small regular files and therefore misses the intended large-file targets. To select files bigger than 10 MiB, you need a leading plus sign, not a minus sign. This is a common syntax mix-up.

  • ✗

    find /var/log -type d -size +10M

    Why it's wrong here

    The `-type d` predicate restricts results to directories, while the question asks for regular files, so any regular files are ignored. Even with `+10M`, directories are almost certain to be far below 10 MiB in size, so this command typically returns nothing at all. To match regular files, the correct type flag is `f`, as in `-type f`. The size clause is irrelevant when the wrong file type is specified.

  • ✗

    find /var/log -type f -size 10M

    Why it's wrong here

    A plain `10M` without a sign matches only files whose size rounds up to exactly 10 MiB, not every file larger than 10 MiB. Files of 15 MiB or 20 MiB round to 15M or 20M and thus do not satisfy `-size 10M`. This creates a narrow, unintended filter that excludes most large files. In find syntax, `+10M` is required to express "greater than 10 MiB."

  • ✓

    find /var/log -type f -size +10M

    Why this is correct

    The plus sign in `-size +10M` is the "greater than" operator, so this command finds all regular files over 10 MiB in /var/log. The `-type f` option filters for regular files only, excluding directories, symlinks, and special files. This is the correct way to identify large files with find.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.