CompTIA Linux+ (XK0-006)System ManagementMedium

A network technician needs to quickly determine which processes are listening on TCP and UDP ports on a Linux server, along with the associated process IDs. Which command provides this information?

  1. Adig server.example.com
  2. Bss -tulpn
  3. Cip route show
  4. Dtraceroute 8.8.8.8
Show answer & explanation

Correct answer: B. ss -tulpn

'ss -tulpn' displays TCP (-t) and UDP (-u) listening (-l) sockets with process names/PIDs (-p) using numeric addresses (-n), making it ideal for identifying which services are bound to which ports.

Why the other options are wrong

  • A. dig performs DNS lookups, unrelated to port listening.
  • C. ip route show displays the routing table, not listening ports.
  • D. traceroute shows the network path to a destination, not local listening ports.

ss Command

A modern replacement for netstat used to display socket statistics, including listening ports and associated processes.

  • -t shows TCP sockets, -u shows UDP sockets
  • -l filters for listening sockets only
  • -p shows the owning process, -n avoids DNS resolution delays

Memory trick: ss = 'socket snapshot' revealing who's listening on the server

More System Management questions