CompTIA Linux+ (XK0-006) practice questions
208 free questions with answers and explanations.
- 1.A technician is troubleshooting a server experiencing slow disk I/O. They suspect a particular disk might be bottlenecking performance. Which command and output column would best indicate if a specific disk is consistently busy and potentially causing the bottleneck?Troubleshooting
- 2.A network administrator needs to allow SSH access on a firewalld-managed server, but only from hosts within the 192.168.1.0/24 subnet, while leaving the default zone's SSH service disabled for all other sources. Which command should be used?Security
- 3.A developer wants to generate a new SSH key pair using the modern Ed25519 algorithm, which offers strong security with smaller key sizes compared to RSA. Which command should the developer run?Security
- 4.A company's compliance policy requires that any local account be automatically locked for 15 minutes after five consecutive failed login attempts. Which PAM configuration change correctly enforces this using pam_faillock on a modern RHEL-based system?Security
- 5.After hardening a server, an administrator initializes a file integrity baseline using AIDE by running aide --init and copying the resulting database into place. Which command should be scheduled via cron to routinely detect unauthorized changes against that baseline?Security
- 6.A server fails to boot and drops to a 'grub rescue>' prompt with the error 'file not found' due to a corrupted /boot/grub2 directory. Which sequence of commands at the grub rescue prompt correctly loads the necessary modules and boots into a normal GRUB environment for further troubleshooting?System Management
- 7.A system administrator is using Ansible to manage a fleet of Linux servers. They need to ensure a specific service, `httpd`, is running and enabled at boot time on all web servers. Which of the following Ansible playbook snippets correctly achieves this goal?Automation, Orchestration and Scripting
- 8.A storage array is configured as RAID 5 using four disks, each with 2TB of raw capacity. What is the approximate usable storage capacity of this array?System Management
- 9.A system administrator needs to write a Bash script that takes a single argument, which is a directory path. The script should verify if the provided path exists and is indeed a directory. If not, it should print an error message and exit with a non-zero status. Which of the following conditional statements correctly performs this check?Automation, Orchestration and Scripting
- 10.An application on a Linux server is running slowly, and a technician suspects disk I/O is the bottleneck. Which command provides extended per-device I/O statistics, including average wait time (await) and percentage of CPU time the device was busy (%util)?System Management
- 11.A junior administrator is configuring a Bash script that processes log files. The script needs to exit immediately if any command fails, to prevent further processing with potentially incorrect data. Which Bash command or construct should be used to ensure this behavior?Automation, Orchestration and Scripting
- 12.An administrator manages both a Debian-based server and a Fedora-based server. On the Fedora server, the administrator needs to add a trusted third-party software repository so 'dnf install' can pull packages from it. Where should the repository definition be placed?System Management
- 13.A technician created a new firewalld zone named 'internal' with restricted services. After running 'firewall-cmd --zone=internal --add-interface=eth0', the assignment worked immediately, but disappeared after the server rebooted. Which command permanently assigns eth0 to the internal zone?Security
- 14.A technician needs to add a second passphrase to an already-encrypted LUKS partition, /dev/sdb1, so that a backup administrator can also unlock the volume, without removing or changing the original passphrase. Which command should the technician run?Security
- 15.A developer is working on a Python script that needs to interact with a REST API. The script uses the `requests` library to make HTTP GET requests and processes the JSON response. During development, the developer wants to store the API key securely and avoid hardcoding it in the script. Which of the following is the MOST secure and flexible way to manage the API key in a Python script?Automation, Orchestration and Scripting
- 16.A system administrator needs to implement a policy where all new files created by any user in the `/shared/data` directory automatically inherit the group ownership of the directory itself, rather than the user's primary group. Which command achieves this?Services and User Management
- 17.A system administrator is using Ansible to ensure that a specific package, `nginx`, is installed on all web servers. They also need to ensure that the `nginx` service is running and enabled to start automatically on boot. Which Ansible task correctly achieves both of these requirements?Automation, Orchestration and Scripting
- 18.An administrator generated a GPG key pair for signing important documents. As a best practice in case the private key is ever lost or compromised, which action should be taken immediately after key generation?Security
- 19.A security engineer is migrating firewall rules from iptables to nftables on a new server and needs to add a rule dropping all incoming TCP traffic on port 23 (Telnet) within the existing inet filter table's input chain. Which command is correct?Security
- 20.An administrator runs 'ssh user@server' and receives the error: 'WARNING: UNPROTECTED PRIVATE KEY FILE!' referencing ~/.ssh/id_rsa. What is the correct fix?Security
- 21.An administrator noticed that after entering a password once for a sudo command, subsequent sudo commands in the same terminal session do not prompt for a password again for several minutes. Which sudoers directive controls the length of this credential caching window?Security
- 22.A web server running SELinux in enforcing mode needs to send outbound mail notifications from PHP scripts, but SELinux is blocking the connection. The administrator wants to permanently allow this behavior without disabling SELinux or relabeling files. Which command should be used?Security
- 23.A systems administrator is deploying a new AppArmor profile for a custom in-house application but is concerned the profile may block legitimate application behavior in production. The administrator wants AppArmor to log policy violations without actually restricting the application's actions. Which command should the administrator run?Security
- 24.A system administrator is configuring a new Linux server and needs to ensure that the `firewalld` service is started automatically every time the system boots up. Which `systemctl` command should the administrator use to achieve this?Services and User Management
- 25.A server's network connection is managed by NetworkManager. A technician manually edits /etc/resolv.conf to add 'nameserver 8.8.8.8', but after a reboot the change is lost and the original DNS server returns. Which command should the technician use instead to permanently set the DNS server for the connection named 'eth0'?System Management
- 26.A technician needs to permanently prevent the 'nouveau' kernel module from loading automatically on system boot because it conflicts with a proprietary NVIDIA driver. Which configuration approach is correct?System Management
- 27.A system administrator is investigating why a critical service, `myapp.service`, fails to start after a system reboot. Upon checking `systemctl status myapp.service`, they see `ExecStart=/usr/local/bin/start_myapp.sh`. They then confirm that `/usr/local/bin/start_myapp.sh` exists and has execute permissions. Which of the following is the most appropriate next step to diagnose why the script itself might be failing when executed by systemd?Troubleshooting
- 28.A system administrator is developing an Ansible playbook for deploying a web application. The application requires a specific configuration file, `app.conf`, which needs to be generated dynamically based on host-specific variables (e.g., `server_port`, `database_url`). Which Ansible module is best suited for creating this configuration file from a template?Automation, Orchestration and Scripting
- 29.A technician is preparing a new 4TB SSD for use and runs 'parted /dev/sdb mkpart primary ext4 0% 100%'. To ensure the partition is created with optimal alignment for SSD performance, which parted invocation should the technician use?System Management
- 30.An administrator is preparing to encrypt a new LUKS-protected partition, /dev/sdb1, for a critical database server. Before deploying it into production, the administrator wants a way to recover the volume if the LUKS header ever becomes corrupted. Which command should be run?Security
- 31.A Linux server is experiencing extremely slow network performance, but CPU utilization and disk I/O appear normal. The administrator suspects an issue with the network interface's duplex settings, potentially causing a duplex mismatch. Which command would allow the administrator to check the current speed and duplex settings of the `eth0` network interface?Troubleshooting
- 32.A server with two network interfaces needs to act as a NAT gateway so that internal clients on eth1 can reach the internet through eth0. Which iptables command correctly enables this masquerading behavior?Security
- 33.A server fails to boot normally and drops into a systemd emergency shell. The journal shows: "[TIME] Timed out waiting for device /dev/sdb1." Investigation reveals /dev/sdb1 is an external USB drive that is not always connected, but it has a standard entry in /etc/fstab. Which fstab mount option should be added to that entry to prevent this boot failure when the device is absent?Troubleshooting
- 34.A security administrator is troubleshooting a web application that is being blocked by SELinux even though standard file permissions are correct. The administrator wants to temporarily switch SELinux into a mode that logs violations without blocking them, without rebooting the server. Which command accomplishes this?Security
- 35.A compliance policy requires that all new local user passwords be at least 14 characters long, enforced through PAM at password creation time. Which file and setting should the administrator configure to meet this requirement?Security
- 36.A technician replaced a failed disk in a BIOS-based server and restored the operating system data to the new disk, /dev/sda. The system fails to boot because no bootloader is installed on the new disk. After booting into a rescue environment and chrooting into the restored system, which command should the technician run to install GRUB onto the disk's boot sector?System Management
- 37.A technician on a Debian-based system wants to see a list of all packages that have available updates without actually installing them. Which command should be used?System Management
- 38.An administrator runs `mdadm --detail /dev/md0` on a RAID 5 array and sees: State : clean, degraded Active Devices : 2 Working Devices : 2 Failed Devices : 1 ... 2 8 33 - removed A new replacement disk has been partitioned as /dev/sdc1. Which command correctly adds this disk back into the array to begin rebuilding?Troubleshooting
- 39.A server can successfully ping other hosts on its local subnet but cannot reach any external IP addresses. Running `ip route show` returns no default route entry. Which command adds a default gateway of 192.168.1.1 through interface eth0?Troubleshooting
- 40.A system administrator has just modified the unit file for a `systemd` service named `myservice.service` (e.g., `/etc/systemd/system/myservice.service`). After saving the changes, the administrator attempts to `systemctl start myservice.service`, but the changes do not seem to take effect. What is the most likely reason for this, and which command should be executed to resolve it?Services and User Management
- 41.A system administrator wants to define a custom `systemd` target named `my-custom.target` that depends on `network-online.target` and `multi-user.target`. This custom target should be reached only after both of its dependencies are active. Which `systemd` unit file configuration snippet correctly defines these dependencies?Services and User Management
- 42.A user needs to quickly encrypt a single file, notes.txt, for personal storage on a USB drive using a shared passphrase rather than public-key cryptography, so that anyone who knows the passphrase can later decrypt it. Which command should the user run?Security
- 43.A technician is preparing a new Linux server for a database application that requires high-performance, redundant storage. They have four new 1TB physical disks (/dev/sdb, /dev/sdc, /dev/sdd, /dev/sde) and plan to use RAID 10. What is the maximum usable storage capacity for this RAID 10 array?System Management
- 44.A technician checks a failed service: `systemctl status app.service` shows: `Active: failed (Result: exit-code)` Running `journalctl -u app.service -xe` reveals: `Permission denied` when the application attempts to open `/var/lib/app/data.db`. The file is owned by root:root with mode 600, but the service runs as user `appuser`. What should the technician do to resolve this?Troubleshooting
- 45.A technician runs 'lsblk' on a server and notices a logical volume /dev/vg_data/lv_apps is mounted at /opt/apps but the underlying volume group vg_data has 20GB of free (unallocated) extents. Management wants the mounted filesystem grown by 10GB without unmounting it, and the filesystem is ext4. Which sequence of commands correctly accomplishes this?System Management
- 46.A server administrator notices that a physical server takes significantly longer to boot than expected. The administrator wants to see a breakdown of how much time each systemd unit took to initialize during the last boot. Which command should be used?System Management
- 47.A technician moved a website's files from /tmp/newsite to /var/www/html using the mv command. Standard Linux permissions are correct, but Apache still cannot serve the pages due to SELinux denials in the audit log. Which command should the technician run to fix the file security contexts to match the default policy for that directory?Security
- 48.A junior administrator is learning Git and has accidentally committed a file containing sensitive information (e.g., a password) to the local repository. They have not yet pushed this commit to a remote server. Which of the following Git commands should be used to remove the sensitive file from the commit history before pushing to the remote repository?Automation, Orchestration and Scripting
- 49.A system administrator needs to check the validity and integrity of installed RPM packages on a critical server. Which command should be used to verify all files belonging to a specific package, such as 'httpd', against its stored metadata and checksums?Security
- 50.The logical volume /dev/vg_data/lv_home is formatted with ext4 and has run out of space. The volume group vg_data has 5GB of free extents. Which sequence of commands correctly extends the logical volume by 5GB and grows the filesystem to use the new space?System Management