CompTIA Linux+ (XK0-006)TroubleshootingHard

A system administrator observes that a Linux server's CPU utilization is consistently high (near 100%) according to `top`, but no single process appears to be consuming excessive CPU. Further investigation using `pidstat -u 1` shows a high `%usr` and `%sys` for the `ksoftirqd` processes. What is the most likely cause for this behavior?

  1. AA runaway user-space application consuming all CPU resources.
  2. BInsufficient available RAM, leading to excessive swapping and I/O wait.
  3. CHigh network interrupt processing, indicating a network bottleneck or faulty NIC.
  4. DDisk I/O bottleneck, causing processes to wait for disk operations.
Show answer & explanation

Correct answer: C. High network interrupt processing, indicating a network bottleneck or faulty NIC.

`ksoftirqd` processes (kernel soft interrupt daemon) are responsible for handling deferred interrupt processing. High `%usr` (user time) and `%sys` (system time) for `ksoftirqd`, especially when overall CPU is high but no single user process is dominant, strongly indicates that the kernel is spending a significant amount of time processing soft interrupts. This is commonly caused by a very busy network interface (NIC) generating a high rate of incoming packets/interrupts that the kernel has to process, leading to a network bottleneck or a faulty NIC overwhelming the CPU.

Why the other options are wrong

  • A. A runaway user-space application would show high CPU for that specific process in `top` or `pidstat`, which the problem statement explicitly negates.
  • B. Insufficient RAM would primarily manifest as high swap activity (checked with `free` or `vmstat si/so`) and potentially high I/O wait (`top wa`), not directly high `ksoftirqd` CPU.
  • D. A disk I/O bottleneck would typically show up as high I/O wait (`top wa`) and potentially high `%util` in `iostat`, not primarily `ksoftirqd` CPU usage.

ksoftirqd CPU Usage

High CPU utilization by `ksoftirqd` processes indicates that the Linux kernel is spending significant time processing 'soft interrupts'. This often points to high network activity (packet processing) or other device-related interrupt overhead, potentially bottlenecking the system.

  • Handles deferred kernel interrupt processing.
  • High usage often linked to network I/O or device drivers.
  • Suggests a bottleneck at the interrupt handling layer.

Memory trick: KSOFTIRQD's buzz means the network's got a big fuss.

More Troubleshooting questions