Courseiva
Essential Tools →mediumMultiple Select

EX200 Essential Tools Practice Question

Which TWO commands can be used to display the contents of a compressed log file without decompressing it first?

⚠ Common exam trap

Many exam-takers assume `less` or `grep` can handle compressed files natively, but they cannot; the correct approach is to use dedicated tools like `zcat`, `zless`, `bzcat`, or `bzless` that perform on-the-fly decompression.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

bzless /var/log/messages.bz2

`bzless` is a utility specifically designed to view bzip2-compressed files without decompressing them first. It decompresses the file on the fly and pipes the output to a pager, allowing you to scroll through the content. Similarly, option B is correct because `zcat` reads a gzip-compressed file and writes the decompressed data to standard output, effectively displaying the contents without permanently decompressing the file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    bzless /var/log/messages.bz2

    Why this is correct

    bzless is the bzip2-aware counterpart of less; it invokes bzip2 to decompress the file on the fly and pipes the output into the less pager. This lets you interactively scroll through /var/log/messages.bz2 without first expanding it to disk, and bzless cleans up any temporary decompression stream when you quit. Because the file is bzip2-compressed, this command correctly renders the log contents.

  • ✓

    zcat /var/log/messages.gz

    Why this is correct

    zcat belongs to the gzip family and writes the decompressed contents of a .gz file directly to standard output. In a terminal, that output is displayed immediately, so you can view the entire log without using gzip -d or gunzip first. You can also pipe zcat's output to less or grep for more controlled viewing, but zcat alone still counts as displaying the file's contents.

  • ✗

    grep 'error' /var/log/messages.gz

    Why it's wrong here

    grep does not decompress files before searching, so it will read the raw gzip binary stream instead of the plain-text log lines. When run against /var/log/messages.gz, it will complain about binary data or produce useless matches like `Binary file ... matches`, and it will never search the logical decompressed content. For compressed logs you need zgrep, or a pipeline like zcat file | grep, to carry out pattern matching on the uncompressed data.

  • ✗

    vim /var/log/messages.gz

    Why it's wrong here

    vim is an editor, and while it can read and transparently decompress a gzip file using Vim's internal autocommands, it also loads the data into an editable buffer and can write changes back as a compressed file. That makes the command a modification tool rather than a display-only utility, and merely opening vim for viewing risks accidental changes or altered compressed output. A read-only pager such as less or zless is the intended way to view logs without editing them.

  • ✗

    less /var/log/messages.gz

    Why it's wrong here

    less is a general-purpose pager, but it has no built-in decompression logic of its own; without a helper like lesspipe configured in LESSOPEN, it will dump the compressed bytes to the terminal as non-printing control codes and mojibake. On some systems less may appear to work because the distribution installs lesspipe, but that behavior is not part of less itself and cannot be assumed. The command zless, which passes through gzip, or bzless for bzip2 files, is the correct way to page a compressed log.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.