Courseiva
Essential Tools →hardMultiple Choice

EX200 Essential Tools Practice Question

During a security audit, an administrator needs to list all TCP ports on which the system is listening, showing only the port numbers and the associated process names. Which command best achieves this?

⚠ Common exam trap

A common mix-up: candidates default to `netstat -tulpn` (Option A) because it is familiar, but Red Hat EX200 emphasizes `ss` as the modern replacement, and the question specifically asks for only TCP ports and process names, making `-u` (UDP) and the lack of `-l` (listening only) in the default `netstat` command incorrect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sudo ss -tlnp

`sudo ss -tlnp` lists TCP listening sockets with numeric port numbers and process names. The `-t` flag filters for TCP, `-l` shows only listening sockets, `-n` displays numeric addresses/ports (avoiding DNS resolution), and `-p` reveals the process name. This command requires root privileges to see process information, hence `sudo`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    netstat -tulpn

    Why it's wrong here

    netstat -tulpn is the classic tool for displaying listening sockets, but it belongs to the deprecated net-tools package, which is not installed by default in modern RHEL systems. Even on systems where it exists, the command combines TCP and UDP listeners (-u) and offers no advantage over ss, while pulling in a legacy dependency that may be missing in a minimal or security-hardened environment. In a RHEL administration context, relying on netstat is therefore a portability and compliance risk, not a correct first-line diagnostic.

  • ✗

    nmap -sT localhost

    Why it's wrong here

    nmap -sT localhost is an external TCP connect scan that probes open ports from the perspective of a network client, not a local socket diagnostic. It performs a full three-way handshake, which creates connection records in system logs and may trigger intrusion detection, and it only tells you whether a port is reachable, not which process owns the listening socket or whether it is actually in the LISTEN state. Since the task is to 'list all' local TCP listeners with their processes, nmap cannot provide the required PID or program name and is the wrong tool entirely.

  • ✓

    sudo ss -tlnp

    Why this is correct

    sudo ss -tlnp is the correct modern command because ss is part of iproute2 and is the standard socket inspection utility in RHEL. The flags -t limit output to TCP, -l show only listening sockets, -n display numeric ports, and -p attach the PID and process name to each entry; sudo is required because process ownership information is only visible to root for sockets belonging to other users. This command directly reads kernel socket tables via /proc and gives a clean, complete list of all TCP listeners.

  • ✗

    lsof -i TCP:1-65535

    Why it's wrong here

    lsof -i TCP:1-65535 lists open files related to TCP sockets across the entire port range, but it does not restrict output to listening sockets—you will also see established connections, TIME-WAIT sockets, and other TCP file descriptors. To isolate listeners you would need an extra filter such as -sTCP:LISTEN, and lsof's file-descriptor-centric view makes the output noisier and less directly focused than ss. Additionally, without sudo, lsof hides process details for sockets owned by other users, and the tool may not be installed by default on all RHEL systems.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.