EX200 Operate running systems Practice Question
Which TWO commands can be used to view recent systemd journal logs for the current boot?
⚠ Common exam trap
Candidates often confuse `--list-boots` (which lists boot IDs) with actually viewing logs, or think that `--since today` is equivalent to `-b`, when in fact `--since today` can span multiple boots if the system has been running for days.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
journalctl -b
`journalctl -b` displays logs from the current boot, which is the default behavior when no boot ID is specified. This command directly queries the systemd journal for messages generated during the current system session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
journalctl -p err
Why it's wrong here
journalctl -p err is incorrect because the -p option filters by syslog priority (err being equivalent to level 3 errors and above), not by boot. This command displays all error-level messages from every boot recorded in the journal, including previous boots if persistent storage is enabled. It does not isolate the current boot's log entries, so it fails to answer 'which commands view recent systemd journal entries' specifically for the active session.
- ✗
journalctl --list-boots
Why it's wrong here
journalctl --list-boots is incorrect because it merely enumerates the boot IDs, timestamps, and sequence numbers of all recorded boots. It does not display the actual journal log messages; it only provides a summary list that can be used as a reference for other journalctl invocations. Thus, while helpful for identifying which boot to query, it is not a command that 'views' journal entries itself.
- ✓
journalctl -b
Why this is correct
journalctl -b is correct because it is the shorthand form of the --boot option, which instructs journald to display only the log messages from the current boot. This is the standard, concise way to view the most recent journal entries generated since the system started, making it ideal for troubleshooting issues in the current session. The -b flag accepts an optional argument like -1 to inspect previous boots, but with no argument it defaults to the current boot.
- ✓
journalctl --boot
Why this is correct
journalctl --boot is correct because it is the long-form equivalent of -b, explicitly selecting the current boot's journal entries. It uses the boot ID stored in the journal to filter out logs from previous boots, ensuring the administrator sees only the systemd-managed messages from the most recent session. This command is equally valid as journalctl -b and is often preferred in scripts for clarity, but both produce identical output.
- ✗
journalctl --since today
Why it's wrong here
journalctl --since today is incorrect because it filters the journal based on a chronological timestamp (midnight today) rather than on boot identity. If the system was rebooted after midnight, this command will include entries from both the previous and current boots, mixing logs from different sessions. It does not isolate the current boot's messages, so it is not a reliable replacement for the boot-centric -b or --boot options.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.