EX200 Essential Tools Practice Question
An administrator needs to terminate a hung process with PID 3456 that does not respond to 'kill -15 3456'. Which signal should be used next?
⚠ Common exam trap
Red Hat often tests the distinction between signals that can be caught/ignored (SIGTERM, SIGHUP) and those that cannot (SIGKILL, SIGSTOP), and candidates may mistakenly choose SIGSTOP (kill -19) thinking it will terminate the process, when it actually only suspends it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kill -9 3456
Kill -9 (SIGKILL) is the signal of last resort for a process that does not respond to SIGTERM (kill -15). SIGKILL cannot be caught, blocked, or ignored by the process; it forces immediate termination by the kernel. Since the process is hung and unresponsive to SIGTERM, SIGKILL is the appropriate next step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kill -9 3456
Why this is correct
SIGKILL (signal 9) is the only signal that the Linux kernel delivers directly, bypassing any user-space signal handler in process 3456. Because neither the process nor its threads can catch, block, or ignore SIGKILL, the kernel immediately terminates the process and reaps its resources, making it the correct last resort for a hung process that has failed to respond to SIGTERM.
- ✗
kill -15 3456
Why it's wrong here
SIGTERM (signal 15) is the default and polite termination request; it asks process 3456 to exit cleanly and run its cleanup routines, but the process has already ignored this signal. A hung process that is stuck in an uninterruptible sleep or a busy loop may never return to user space to handle SIGTERM, so the request remains pending and the process survives.
- ✗
kill -19 3456
Why it's wrong here
SIGSTOP (signal 19) is a job-control signal that halts process 3456's execution immediately, leaving it in a stopped state (similar to Ctrl+Z) but still present in memory and the process table. It does not remove the process; it can be resumed with SIGCONT (signal 18), so it stops the hang temporarily but does not fulfill the requirement to terminate the process.
- ✗
kill -1 3456
Why it's wrong here
SIGHUP (signal 1) originally notifies a process that its controlling terminal has hung up, and many daemons interpret it as an instruction to reload configuration files. For a process that is already hung, SIGHUP is often caught by a handler or ignored altogether, so it neither guarantees termination nor clears the stuck state, leaving the administrator without a resolved process.
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.