EX200 Operate running systems Practice Question
After a system crash, an administrator needs to review logs from the previous boot. Which command shows only logs from the boot before the current one?
⚠ Common exam trap
A common mix-up: candidates confuse the offset numbering: `-b 0` refers to the current boot, not the previous one, leading them to select option D, while the correct offset for the previous boot is `-1`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
journalctl -b -1
The `journalctl -b -1` command shows logs from the previous boot by using the `-b` (boot) option with an offset of `-1`, which refers to the boot session immediately before the current one. This is the correct way to access historical boot logs in systems using systemd-journald, as the journal retains logs from multiple boots by default.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
journalctl -b -1
Why this is correct
journalctl -b -1 displays the journal entries from the boot immediately preceding the current one, using a boot offset of -1. This is the appropriate command after a system crash because it lets you inspect the logs from the crashed boot without including the current recovery boot's messages. For this to work, the journal must be persisted across reboots, typically in /var/log/journal, rather than only in memory.
- ✗
dmesg -b -1
Why it's wrong here
The dmesg command reads the kernel ring buffer, which by design contains only messages from the currently running kernel; it does not retain logs from previous boots. There is no -b option in dmesg to select a boot, unlike journalctl, so invoking dmesg -b -1 would produce an invalid option error. To read earlier boot messages, you must rely on the systemd journal rather than dmesg.
- ✗
cat /var/log/boot.log
Why it's wrong here
The /var/log/boot.log file, when it exists, is written during the current boot and typically holds only that boot's early startup messages. It is not a historical log and does not capture the previous crashed boot; in fact, on modern systemd-based distributions such as RHEL 8/9, this file may not even be present because boot logging is handled by journald. Therefore, reading this file cannot satisfy the need to review logs from before the crash.
- ✗
journalctl -b 0
Why it's wrong here
journalctl -b 0 selects the current boot (offset 0), which is the boot that started after the crash. While this is a valid journalctl command, it shows only the post-crash boot's messages, not the logs from the boot that failed. To examine the previous boot, you need -b -1; using -b 0 would show the recovery process, not the cause of the crash.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.