CompTIA Linux+ (XK0-006)TroubleshootingEasy

A system administrator is investigating a Linux server that unexpectedly rebooted. The last messages in `/var/log/messages` (or `journalctl`) before the reboot show entries indicating "Out of memory: Kill process ... or sacrifice child". Which kernel mechanism is responsible for terminating processes in such a low-memory situation?

  1. AThe `kswapd` process.
  2. BThe `systemd` watchdog timer.
  3. CThe kernel panic handler.
  4. DThe OOM (Out-Of-Memory) Killer.
Show answer & explanation

Correct answer: D. The OOM (Out-Of-Memory) Killer.

The "Out of memory: Kill process..." message is a clear indicator that the Linux kernel's Out-Of-Memory (OOM) Killer has been activated. Its purpose is to free up memory by terminating processes when the system runs critically low on available RAM, preventing a complete system freeze or kernel panic.

Why the other options are wrong

  • A. The `kswapd` process is responsible for managing virtual memory and swapping pages to/from disk, but it doesn't kill processes; it tries to free memory by swapping.
  • B. The `systemd` watchdog timer reboots the system if a service or the system hangs, but doesn't specifically kill processes due to low memory.
  • C. A kernel panic handler is invoked for unrecoverable kernel errors, which is a more severe event than simply running out of memory (though OOM can lead to panic if not handled).

OOM Killer (Out-Of-Memory Killer)

The OOM Killer is a Linux kernel mechanism that identifies and terminates processes when the system runs out of physical memory, aiming to prevent a complete system crash or unresponsiveness.

  • Triggered when the kernel cannot allocate more memory.
  • Chooses processes based on factors like memory usage, CPU time, and oom_score.
  • Logs messages like 'Out of memory: Kill process...' to the system journal/logs.

Memory trick: When 'O'ut 'O'f 'M'emory, the 'OOM' Killer executes.

More Troubleshooting questions