EX200 Essential Tools Practice Question
Which TWO commands can be used to view the kernel ring buffer?
⚠ Common exam trap
Test-takers frequently confuse general log viewing commands (like `journalctl -f` or `cat /var/log/messages`) with the specific tools designed to read the kernel ring buffer, or forget that `journalctl -k` is the systemd-native way to access kernel messages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dmesg
The kernel ring buffer stores kernel-related messages, such as hardware driver and boot messages. The `dmesg` command is specifically designed to print or control this buffer, making it a direct and correct tool for viewing kernel ring buffer messages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
journalctl -f
Why it's wrong here
journalctl -f tails the systemd journal in real time, following new entries as they are appended from all configured sources, including services, kernel messages, and user logs. It is not a query for the kernel ring buffer itself; using -f merely follows the journal stream, and kernel messages would only appear if they happen to be written to the journal after the command is run. Its purpose is live log streaming, not reviewing the kernel's internal ring buffer.
- ✓
dmesg
Why this is correct
dmesg is the canonical command for viewing the kernel ring buffer, a fixed-size circular buffer in kernel memory where the kernel stores its own messages, such as driver initialization, hardware detection, and early boot errors. It reads from the buffer directly via the syslog(2) system call or /dev/kmsg, providing a concise snapshot of kernel-level events. This is the primary, in-memory source for kernel logs, not a file or a systemd-specific interface.
- ✗
cat /var/log/messages
Why it's wrong here
cat /var/log/messages reads a plain-text log file that historically contains general system messages written by syslog daemons like rsyslog. While kernel messages are often copied into this file by syslog/journald, it is not the kernel ring buffer itself; the ring buffer lives in kernel memory and is independent of any log file. The file may be truncated or rotated, and its contents reflect what was forwarded to the logging daemon, not the full kernel buffer.
- ✗
systemctl status
Why it's wrong here
systemctl status is designed to inspect the state and configuration of systemd units, such as services, sockets, and mounts, displaying their active status, process tree, and recent log lines from the systemd journal. It does not access the kernel ring buffer, and unless a service happens to be the kernel (which no unit is), this command will never display the raw kernel messages. Its log output is a filtered view of unit-related journal entries, not a dedicated kernel message viewer.
- ✓
journalctl -k
Why this is correct
journalctl -k extracts kernel messages from the persistent systemd journal, which are collected by systemd-journald from /dev/kmsg and stored on disk or in memory. Unlike dmesg, it does not read the live ring buffer directly but instead shows a timestamped, indexed copy of kernel messages that the journal has captured. As a correct answer, it provides a reliable way to query kernel logs on modern systems, though it is technically a journal-based view of kernel messages rather than the raw ring buffer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.