Courseiva

EX200 Deploy, configure, and maintain systems Practice Question

A user reports that they cannot start a service. Which command would an administrator use to view the service's journal logs since last boot?

⚠ Common exam trap

The trap here is that candidates often forget the `-u` flag is mandatory to filter for a specific service unit, mistakenly thinking `journalctl service` is valid, or they confuse `journalctl -b` (all logs since boot) with the more targeted command needed for service-specific troubleshooting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

journalctl -u service -b

`journalctl -u service -b` combines the `-u` flag to filter logs for a specific systemd unit (the service) with the `-b` flag to show only logs from the current boot. This is the precise command an administrator would use to view a service's journal logs since the last system start, directly addressing the user's inability to start the service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    journalctl -b

    Why it's wrong here

    The `journalctl -b` command displays the entire system journal for the current boot, including kernel messages, user session logs, and every systemd unit. While it does limit output to the current boot, it lacks the `-u` unit filter, so the user would have to manually scan through often thousands of lines to find the specific service's entries. This makes it an inefficient and incomplete tool for diagnosing a single service's startup failure.

  • ✓

    journalctl -u service -b

    Why this is correct

    Running `journalctl -u service -b` combines the `--unit` filter with the `--boot` option, instructing systemd's journal to display only log records belonging to the specified service unit within the current boot cycle. This is the precise diagnostic command because it isolates the service's own output, errors, and exit status messages. It also automatically appends `.service` to the name if omitted, making it the recommended method for checking why a service failed to start.

  • ✗

    journalctl service

    Why it's wrong here

    The command `journalctl service` is syntactically incorrect because `journalctl` expects options like `-u` and does not use a bare positional argument as a service name. In practice it will either produce an error or, if it parses the argument as a time specifier or match string, display an unfiltered portion of the journal. Without the `-u` flag there is no unit-based filtering, and without `-b` it may include logs from previous boots, both of which prevent isolating the service's current startup problem.

  • ✗

    dmesg | grep service

    Why it's wrong here

    `dmesg` reads the kernel ring buffer, which contains boot-time kernel messages and hardware-related output, not the userspace journal entries produced by systemd services. Piping it through `grep service` would only show lines that happen to contain that string, such as a kernel module named after the service, and would miss the actual application logs or the service's own stderr/stdout. This approach is not only unreliable but also requires root privileges, whereas `journalctl -u service -b` works with normal authorization.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.