CompTIA Linux+ (XK0-006) — Questions and Answers
Question 1: How do you add an existing user 'alice' to the supplementary group 'sudo' without removing her from other groups?
- usermod -aG sudo alice (Correct answer)
- gpasswd sudo alice
- usermod -g sudo alice
- groupmod -a alice sudo
Correct answer: usermod -aG sudo alice
usermod -aG appends the group without replacing existing supplementary group memberships.
Question 2: What does 'find / -perm -4000' search for?
- Files with the SUID bit set (Correct answer)
- Files owned by root
- World-writable files
- Files readable by all users
Correct answer: Files with the SUID bit set
-perm -4000 matches files where the SUID bit (4000) is set, which can be a privilege escalation risk.
Question 3: What does the `apt-cache depends` command show?
- Circular dependency chains
- Optional recommended packages only
- The dependencies that a package requires (Correct answer)
- Packages that depend on the given package
Correct answer: The dependencies that a package requires
`apt-cache depends package` lists the direct dependencies (Depends, Recommends, Suggests) that the specified package declares.
Question 4: What is a bind mount in the context of container security?
- Restricting a container to a specific CPU core
- Binding a container's network namespace to the host
- Mounting a host directory into a container, potentially exposing host files (Correct answer)
- Locking a container's filesystem as read-only
Correct answer: Mounting a host directory into a container, potentially exposing host files
Bind mounts share a host path inside a container; if sensitive directories like /etc are mounted, they can be read or modified by the container.
Question 5: What does the 'dm-crypt' subsystem provide in Linux?
- RAM disk encryption
- Transparent block-level encryption via the device mapper (Correct answer)
- Filesystem-level encryption for ext4
- Network-attached storage encryption
Correct answer: Transparent block-level encryption via the device mapper
dm-crypt is a Linux kernel device mapper target that provides transparent encryption of block devices using the kernel crypto API.
Question 6: In Linux practice, what is the CORRECT sequence when performing a technical procedure?
- Execute immediately and document only if issues arise
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute, then plan and review
- Document, execute, then plan
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows a systematic approach: plan the procedure, prepare necessary resources, execute according to standards, verify results meet specifications, and document the process and outcomes. This ensures quality and accountability.
Question 7: Which command forces all users to change their passwords on their next login?
- chage --reset-all username
- usermod --force-reset username
- passwd --expire username
- chage -d 0 username (Correct answer)
Correct answer: chage -d 0 username
chage -d 0 sets the last password change date to epoch, forcing an immediate password change at next login.
Question 8: When a Linux professional encounters an unexpected result during a technical procedure, the FIRST action should be to:
- Report the issue without any preliminary assessment
- Repeat the procedure from the beginning immediately
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Continue the procedure and address it later
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess the situation when unexpected results occur is critical. This allows the professional to evaluate whether it is safe and appropriate to continue, and to determine if additional guidance or resources are needed.
Question 9: Which skill is most critical for effective process management?
- Technical expertise alone
- Individual work preferences
- Speed of decision-making
- Communication and stakeholder engagement (Correct answer)
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 10: Which iptables chain is used to filter packets destined for the local system?
- OUTPUT
- INPUT (Correct answer)
- PREROUTING
- FORWARD
Correct answer: INPUT
The INPUT chain processes packets whose destination is the local host.
Question 11: What is the result of `echo "${var:-default}"` when `var` is unset?
- Prints nothing
- Prints '$var'
- Prints 'default' (Correct answer)
- Causes an error
Correct answer: Prints 'default'
`${var:-default}` expands to `default` if `var` is unset or empty, without modifying `var`.
Question 12: What command allows you to add a permanent rule in firewalld to open port 443/tcp in the public zone?
- firewall-cmd --open=443/tcp --permanent
- firewall-cmd --add-port=443 --zone=public
- firewall-cmd --zone=public --add-port=443/tcp --permanent (Correct answer)
- firewall-cmd --zone=public --port=443 --enable
Correct answer: firewall-cmd --zone=public --add-port=443/tcp --permanent
The correct syntax uses --add-port=443/tcp with --permanent to persist the rule across reboots, followed by --reload to apply it.
Question 13: What command sets a user's account expiration date to January 1, 2025?
- usermod -e 2025-01-01 username
- chage -E 2025-01-01 username (Correct answer)
- passwd --expire 2025-01-01 username
- useradd -x 2025-01-01 username
Correct answer: chage -E 2025-01-01 username
chage -E sets the account expiration date using YYYY-MM-DD format.
Question 14: Which command adds a rich rule in firewalld to block all traffic from the IP 192.168.1.100?
- firewall-cmd --block-ip=192.168.1.100
- firewall-cmd --add-rich-rule='rule family=ipv4 source address=192.168.1.100 drop' (Correct answer)
- firewall-cmd --add-rule='rule family=ipv4 source address=192.168.1.100 drop'
- firewall-cmd --zone=public --reject-source=192.168.1.100
Correct answer: firewall-cmd --add-rich-rule='rule family=ipv4 source address=192.168.1.100 drop'
firewalld rich rules use the '--add-rich-rule' flag with a structured rule string to allow complex matching conditions.
Question 15: How do you append a line to a file inside a shell script without overwriting it?
- echo 'line' | file
- echo 'line' >> file (Correct answer)
- echo 'line' >| file
- echo 'line' > file
Correct answer: echo 'line' >> file
`>>` appends to a file; `>` truncates and overwrites.
Question 16: How do you pass the value of variable `name` to a script as its first argument and access it inside?
- ./script.sh name; access as $name
- ./script.sh $name; access as ${name}
- ./script.sh "$name"; access as $1 (Correct answer)
- ./script.sh $name; access as $0
Correct answer: ./script.sh "$name"; access as $1
Arguments are passed on the command line and accessed inside the script as positional parameters `$1`, `$2`, etc.
Question 17: What does the `-f` flag test for in `[ -f filename ]`?
- File exists and is executable
- File exists and is a directory
- File exists and is a regular file (Correct answer)
- File exists and is not empty
Correct answer: File exists and is a regular file
`-f` checks that the path exists and is a regular file (not a directory or device).
Question 18: What does the `blkid` command display?
- Block size information for all filesystems
- I/O block statistics per device
- Blocked device access attempts from security policies
- Block device attributes including UUID, filesystem type, and label (Correct answer)
Correct answer: Block device attributes including UUID, filesystem type, and label
blkid probes block devices and displays their UUID, filesystem type, label, and other attributes — essential for writing stable /etc/fstab entries.
Question 19: Which tool is used to audit Linux system calls made by a process for security analysis?
- auditd
- lsof
- ltrace
- strace (Correct answer)
Correct answer: strace
strace intercepts and records system calls made by a process, useful for identifying suspicious behavior.
Question 20: Which RAID level requires a minimum of 4 disks and provides both striping and dual-parity?
- RAID 5
- RAID 6 (Correct answer)
- RAID 50
- RAID 10
Correct answer: RAID 6
RAID 6 uses dual distributed parity, can survive two simultaneous disk failures, and requires a minimum of 4 disks.
Question 21: Which signal is used to reload a daemon's configuration file without restarting it?
- SIGKILL (9)
- SIGTERM (15)
- SIGHUP (1) (Correct answer)
- SIGUSR1 (10)
Correct answer: SIGHUP (1)
SIGHUP (1) was originally a 'hangup' signal but many daemons handle it as a cue to reload their configuration files.
Question 22: What does `$(command)` do in a shell script?
- Runs the command in a subshell and discards output
- Executes the command in the background
- Captures the command's stdout as a string (Correct answer)
- Pipes command output to /dev/null
Correct answer: Captures the command's stdout as a string
Command substitution `$(...)` replaces itself with the standard output of the enclosed command.
Question 23: On a Debian system, which file lists the configured APT repositories?
- /etc/sources.conf
- /etc/apt/sources.list (Correct answer)
- /var/lib/apt/repos
- /etc/apt/packages.list
Correct answer: /etc/apt/sources.list
`/etc/apt/sources.list` (and files in `/etc/apt/sources.list.d/`) define where APT looks for packages.
Question 24: What is the fundamental principle behind networking in the Linux domain?
- Using the newest technology exclusively
- Cost minimization at all costs
- Balancing performance, reliability, and efficiency (Correct answer)
- Following a single vendor solution
Correct answer: Balancing performance, reliability, and efficiency
Effective technical design requires balancing performance requirements with reliability needs and operational efficiency.
Question 25: Which factor MOST significantly affects the quality of technical outcomes in Linux practice?
- The brand of equipment being used
- The practitioner's training, preparation, and attention to detail (Correct answer)
- The time of day the procedure is performed
- The speed at which procedures are completed
Correct answer: The practitioner's training, preparation, and attention to detail
The quality of technical outcomes depends primarily on the practitioner's level of training, thorough preparation, and careful attention to detail. While equipment matters, the professional's competence is the most significant factor.
Question 26: When a Linux professional encounters an unexpected result during a technical procedure, the FIRST action should be to:
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Continue the procedure and address it later
- Repeat the procedure from the beginning immediately
- Report the issue without any preliminary assessment
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess the situation when unexpected results occur is critical. This allows the professional to evaluate whether it is safe and appropriate to continue, and to determine if additional guidance or resources are needed.
Question 27: Which construct in bash properly iterates over all files in the current directory?
- for f in *; do echo "$f"; done (Correct answer)
- for f in $(ls); do echo $f; done
- loop f in *; do echo $f; done
- foreach f in *; do echo $f; done
Correct answer: for f in *; do echo "$f"; done
Using glob `*` directly is safer than parsing `ls` output, which breaks on filenames with spaces.
Question 28: What is the most effective approach to package management in the Linux field?
- Following competitors
- Reactive problem-solving
- Maintaining the status quo
- Systematic planning and continuous improvement (Correct answer)
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 29: What does the `iptables -L` command do?
- Links two network interfaces
- Logs dropped packets to syslog
- Loads a new ruleset from a file
- Lists all current firewall rules (Correct answer)
Correct answer: Lists all current firewall rules
`iptables -L` lists all rules in all chains of the filter table, showing the current firewall policy.
Question 30: What is the output of `echo $((3 ** 2))` in bash?
- 32
- Error
- 9 (Correct answer)
- 6
Correct answer: 9
`**` is the exponentiation operator in bash arithmetic; `3 ** 2` equals 9.
Question 31: What does the `iptables -t nat -A PREROUTING` command affect?
- All forwarded packets after routing
- Packets after they have been routed, for source address translation
- Only locally generated packets being sent out
- Packets before the routing decision is made, typically used for Destination NAT (DNAT) (Correct answer)
Correct answer: Packets before the routing decision is made, typically used for Destination NAT (DNAT)
PREROUTING in the nat table is used for DNAT — redirecting traffic destined for one address/port to another before the routing decision.
Question 32: When using `visudo`, what is the correct syntax to allow user 'dave' to run all commands as root without a password?
- dave ALL=(ALL) ALL
- ALL dave=(root) NOPASSWD
- dave ALL=NOPASSWD ALL
- dave ALL=(ALL) NOPASSWD: ALL (Correct answer)
Correct answer: dave ALL=(ALL) NOPASSWD: ALL
The NOPASSWD: keyword in the sudoers rule skips password prompting for the specified commands.
Question 33: Which option makes `apt-get` automatically remove packages that were installed as dependencies but are no longer needed?
- apt-get remove --auto
- apt-get clean
- apt-get autoremove (Correct answer)
- apt-get purge --orphans
Correct answer: apt-get autoremove
`apt-get autoremove` removes orphaned dependency packages that are no longer required by any installed package.
Question 34: Which firewalld command adds a service permanently to the public zone?
- firewall-cmd --zone=public --add-service=http --permanent (Correct answer)
- firewall-cmd --zone=public --open=http
- firewall-cmd --add-service=http --zone=public
- firewall-cmd --permanent --service=http
Correct answer: firewall-cmd --zone=public --add-service=http --permanent
The --permanent flag makes the rule persist across reboots; without it the change is runtime-only.
Question 35: Which command displays the process tree showing parent-child relationships?
- ps -ef
- procstat
- top -H
- pstree (Correct answer)
Correct answer: pstree
pstree displays running processes as a tree, visually showing parent-child relationships between processes.
Question 36: Which nftables command lists all current rules and tables?
- nft -L
- nft list ruleset (Correct answer)
- nft show rules
- nft display all
Correct answer: nft list ruleset
nft list ruleset displays the complete ruleset including all tables, chains, and rules in a human-readable format.
Question 37: What does `journalctl --since '1 hour ago'` do?
- Shows all journal entries from the last hour until now (Correct answer)
- Shows journal entries from exactly one hour ago only
- Exports one hour of logs to a file
- Deletes journal entries older than one hour
Correct answer: Shows all journal entries from the last hour until now
`--since` filters journal output to show entries from the specified time to the present.
Question 38: What security risk is introduced by having a world-writable /tmp directory without the sticky bit?
- The system logs are corrupted
- Files in /tmp are exposed to the network
- Programs cannot create temporary files
- Any user can delete or overwrite other users' files (Correct answer)
Correct answer: Any user can delete or overwrite other users' files
Without the sticky bit, any user with write access to /tmp can delete files owned by other users, enabling attacks like symlink races.
Question 39: Which iptables module limits the rate of log messages to prevent log flooding?
- -m rate
- -m quota
- -m throttle
- -m limit (Correct answer)
Correct answer: -m limit
The 'limit' module restricts how frequently a rule matches, commonly paired with LOG to prevent syslog from being overwhelmed.
Question 40: Which professional attribute is most valued in permissions within the Linux field?
- Accountability and commitment to standards (Correct answer)
- Avoiding challenging situations
- Working in isolation
- Prioritizing personal convenience
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 41: What does `${arr[@]}` expand to when `arr` is a bash array?
- The number of elements in the array
- The first element only
- The last element only
- All array elements as separate words (Correct answer)
Correct answer: All array elements as separate words
`${arr[@]}` expands each element as a separate word, preserving elements with spaces when quoted.
Question 42: What is the minimum number of days between password changes controlled by in /etc/shadow?
- Field 3 — last change date
- Field 5 — maximum password age
- Field 4 — minimum password age (Correct answer)
- Field 6 — warning period
Correct answer: Field 4 — minimum password age
The fourth field in /etc/shadow sets the minimum number of days a user must wait before changing their password again.
Question 43: Which principle states that users should only have access necessary for their role?
- Need to share
- Principle of least privilege (Correct answer)
- Defense in depth
- Separation of duties
Correct answer: Principle of least privilege
The principle of least privilege ensures users only have the minimum access rights needed to perform their job functions, limiting potential damage.
Question 44: In Linux practice, what is the best approach to quality improvement in permissions?
- Copy what other organizations do without analysis
- Wait for problems to occur before acting
- Use data-driven methods with measurable outcomes (Correct answer)
- Make changes without measuring results
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 45: Which iptables command displays the packet and byte counters for all rules in the INPUT chain?
- iptables -L INPUT
- iptables -n INPUT
- iptables -S INPUT
- iptables -L INPUT -v (Correct answer)
Correct answer: iptables -L INPUT -v
The -v (verbose) flag adds packet and byte counters to the iptables listing output.
Question 46: Which `getopts` call correctly processes a flag `-v` and an option `-o` that takes an argument?
- getopts "-v -o:" opt
- getopts "v|o:" opt
- getopts "vo:" opt (Correct answer)
- getopts "v:o" opt
Correct answer: getopts "vo:" opt
In `getopts`, a colon after a letter means it takes an argument; `vo:` means `-v` is a flag and `-o` requires a value.
Question 47: Which factor MOST significantly affects the quality of technical outcomes in Linux practice?
- The time of day the procedure is performed
- The practitioner's training, preparation, and attention to detail (Correct answer)
- The brand of equipment being used
- The speed at which procedures are completed
Correct answer: The practitioner's training, preparation, and attention to detail
The quality of technical outcomes depends primarily on the practitioner's level of training, thorough preparation, and careful attention to detail. While equipment matters, the professional's competence is the most significant factor.
Question 48: Which command checks the integrity of installed RPM packages against their checksums?
- rpm --verify-all
- checksum --rpm
- yum integrity check
- rpm -Va (Correct answer)
Correct answer: rpm -Va
rpm -Va verifies all installed packages, reporting any files that differ from the original package metadata.
Question 49: What is the purpose of the /etc/sudoers file?
- Store hashed passwords for sudo users
- Set password expiration policies
- Define which users can run commands as root or another user (Correct answer)
- Log all sudo command executions
Correct answer: Define which users can run commands as root or another user
/etc/sudoers specifies user and group privileges for running commands via sudo.
Question 50: What is the function of the /etc/hosts.deny file in TCP Wrappers?
- Prevents listed hosts from logging in via SSH only
- Specifies hosts denied access to wrapped network services (Correct answer)
- Blocks hosts at the firewall level
- Denies DNS resolution for listed hosts
Correct answer: Specifies hosts denied access to wrapped network services
TCP Wrappers checks /etc/hosts.allow first; if no match, /etc/hosts.deny is checked to block access to wrapped services.
Question 51: Which nftables hook corresponds to locally generated outbound traffic on a Linux host?
- input
- output (Correct answer)
- prerouting
- forward
Correct answer: output
The 'output' hook in nftables processes packets generated by local processes before they leave the network interface.
Question 52: In Linux practice, what is the CORRECT sequence when performing a technical procedure?
- Plan, prepare, execute, verify, and document (Correct answer)
- Document, execute, then plan
- Execute, then plan and review
- Execute immediately and document only if issues arise
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows a systematic approach: plan the procedure, prepare necessary resources, execute according to standards, verify results meet specifications, and document the process and outcomes. This ensures quality and accountability.
Question 53: How should Linux professionals handle technical procedures that have been updated or revised?
- Continue using the original method if it still works
- Wait for mandatory enforcement before changing
- Review the updates, complete any required training, and implement the revised procedures (Correct answer)
- Only apply updates to new cases or projects
Correct answer: Review the updates, complete any required training, and implement the revised procedures
When procedures are updated, professionals must review the changes, complete any required training to understand the rationale and new requirements, and implement the revised procedures in their practice. Continuing outdated methods risks non-compliance and suboptimal outcomes.
Question 54: How should Linux professionals handle technical procedures that have been updated or revised?
- Review the updates, complete any required training, and implement the revised procedures (Correct answer)
- Only apply updates to new cases or projects
- Wait for mandatory enforcement before changing
- Continue using the original method if it still works
Correct answer: Review the updates, complete any required training, and implement the revised procedures
When procedures are updated, professionals must review the changes, complete any required training to understand the rationale and new requirements, and implement the revised procedures in their practice. Continuing outdated methods risks non-compliance and suboptimal outcomes.
Question 55: What is the function of the /etc/fstab file during the boot process?
- It tells the kernel which modules to load
- It defines the order in which services start
- It specifies filesystems to mount at boot (Correct answer)
- It lists valid login shells for users
Correct answer: It specifies filesystems to mount at boot
/etc/fstab defines filesystems and their mount points, mount options, and whether they should be checked/mounted at boot.
Question 56: What is the effect of `trap 'rm -f /tmp/tmpfile' EXIT` in a script?
- Deletes the file only if the script exits with an error
- Traps the EXIT signal and ignores it
- Runs the cleanup command whenever the script exits for any reason (Correct answer)
- Prevents the script from exiting until the file is removed
Correct answer: Runs the cleanup command whenever the script exits for any reason
`trap CMD EXIT` registers a command to run automatically whenever the script exits, enabling reliable cleanup.
Question 57: Which command shows all open network ports and the processes listening on them?
- ifconfig -ports
- lsof -i
- netstat -a
- ss -tlnp (Correct answer)
Correct answer: ss -tlnp
ss -tlnp shows TCP listening ports (-t -l), numeric addresses (-n), and the owning process (-p).
Question 58: What is the default behavior of GRUB2 when no kernel is selected during the timeout?
- It halts and waits indefinitely
- It boots the default (first highlighted) menu entry (Correct answer)
- It boots into rescue mode
- It reboots the system
Correct answer: It boots the default (first highlighted) menu entry
GRUB2 automatically boots the default entry once the timeout expires, which is typically the first or most recent kernel.
Question 59: What role does calibration play in maintaining technical accuracy for Linux professionals?
- It only matters during formal inspections
- It is only necessary for new equipment
- It ensures instruments and methods produce accurate, consistent results over time (Correct answer)
- It is an optional best practice for advanced professionals
Correct answer: It ensures instruments and methods produce accurate, consistent results over time
Regular calibration ensures that instruments, tools, and methods continue to produce accurate and consistent results over time. Without calibration, measurement drift and equipment wear can lead to unreliable outcomes.
Question 60: How does the Linux body of knowledge relate to daily professional practice?
- It only applies during certification exams
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
- It is theoretical and has limited practical application
- It is relevant only for academic research
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 61: What is XFS and what type of workloads is it best suited for?
- A compressed filesystem optimized for small files
- A network filesystem designed for distributed storage
- A high-performance journaling filesystem best suited for large files and parallel I/O workloads (Correct answer)
- A filesystem designed specifically for SSDs
Correct answer: A high-performance journaling filesystem best suited for large files and parallel I/O workloads
XFS excels at large file performance, parallel access patterns, and scales to very large filesystems — making it default in RHEL for enterprise storage workloads.
Question 62: In Linux practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Document it for the next safety audit
- Wait for a supervisor to notice the issue
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels. Delaying action increases the risk of incidents.
Question 63: Which command shows detailed information about a file's inode, including all timestamps?
- stat filename (Correct answer)
- ls -li filename
- file --info filename
- inode filename
Correct answer: stat filename
stat displays all inode information: size, blocks, inode number, permissions, UID/GID, all three timestamps (atime, mtime, ctime), and device info.
Question 64: What does the 'nice' value range from in Linux?
- 1 to 40
- -19 to 20
- 0 to 39
- -20 to 19 (Correct answer)
Correct answer: -20 to 19
Linux nice values range from -20 (highest priority) to 19 (lowest priority), with 0 as the default.
Question 65: Which practice improves the security of shell scripting implementations?
- Disabling all logging
- Using default credentials
- Granting maximum permissions to all users
- Input validation and principle of least privilege (Correct answer)
Correct answer: Input validation and principle of least privilege
Input validation prevents injection attacks while the principle of least privilege limits the damage potential of any compromised component.
Question 66: What does 'nohup command &' accomplish?
- Runs command at higher priority in background
- Runs command with no output buffering
- Pauses command until terminal reconnects
- Runs command immune to SIGHUP and detached from terminal (Correct answer)
Correct answer: Runs command immune to SIGHUP and detached from terminal
nohup ignores the SIGHUP signal (sent when a terminal closes) and & puts the process in the background, so it survives terminal logout.
Question 67: What does the glob pattern `ls /etc/*.conf` match?
- All files in /etc containing 'conf' in their name
- All files in /etc ending with .conf (Correct answer)
- Only hidden .conf files in /etc
- All .conf files anywhere on the system
Correct answer: All files in /etc ending with .conf
The `*` wildcard matches any string of characters, so `*.conf` matches all files ending with `.conf` in `/etc`.
Question 68: Which approach is MOST important for Linux professionals when applying technical procedures?
- Adhering to established protocols while adapting to specific conditions (Correct answer)
- Following personal shortcuts developed through experience
- Applying the same technique in every situation without variation
- Using the fastest method available regardless of standards
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to established protocols as a foundation, with professional judgment to adapt appropriately to specific conditions. This balance ensures both consistency and effectiveness.
Question 69: What role does calibration play in maintaining technical accuracy for Linux professionals?
- It is an optional best practice for advanced professionals
- It only matters during formal inspections
- It is only necessary for new equipment
- It ensures instruments and methods produce accurate, consistent results over time (Correct answer)
Correct answer: It ensures instruments and methods produce accurate, consistent results over time
Regular calibration ensures that instruments, tools, and methods continue to produce accurate and consistent results over time. Without calibration, measurement drift and equipment wear can lead to unreliable outcomes.
Question 70: What does setting OOM score adjustment (oom_score_adj) to -1000 for a process do?
- Triggers immediate memory compaction for the process
- Makes the process the first target for the OOM killer
- Makes the process completely immune to the OOM killer (Correct answer)
- Doubles the process's memory allocation limit
Correct answer: Makes the process completely immune to the OOM killer
An oom_score_adj of -1000 disables OOM killing for that process, used to protect critical system daemons from being killed under memory pressure.
Question 71: Which command would you use to check the SMART status of a hard drive `/dev/sda`?
- badblocks -v /dev/sda
- iostat -d /dev/sda
- hdparam -S /dev/sda
- smartctl -a /dev/sda (Correct answer)
Correct answer: smartctl -a /dev/sda
`smartctl -a` from the `smartmontools` package reads and displays all SMART data for the specified drive.
Question 72: Which log file records failed and successful sudo usage on most Linux distributions?
- /var/log/messages
- /var/log/sudo.log
- /var/log/auth.log or /var/log/secure (Correct answer)
- /var/log/syslog
Correct answer: /var/log/auth.log or /var/log/secure
Authentication events including sudo use are written to /var/log/auth.log (Debian-based) or /var/log/secure (RHEL-based).
Question 73: You want to find all files modified in the last 24 hours under `/var/log`. Which command is correct?
- find /var/log -mtime -1 (Correct answer)
- ls -lt /var/log | head
- find /var/log -mtime 1
- find /var/log -newer 24
Correct answer: find /var/log -mtime -1
`-mtime -1` matches files modified less than 1 day (24 hours) ago; the minus sign means 'less than'.
Question 74: Which file configures systemd-networkd or NetworkManager for a network interface on modern systems?
- /etc/hosts
- /proc/net/dev
- /etc/resolv.conf
- /etc/network/interfaces on Debian or /etc/sysconfig/network-scripts/ on RHEL (Correct answer)
Correct answer: /etc/network/interfaces on Debian or /etc/sysconfig/network-scripts/ on RHEL
Interface configuration lives in `/etc/network/interfaces` on Debian-based systems or `/etc/sysconfig/network-scripts/` on RHEL-based systems.
Question 75: Which approach is MOST important for Linux professionals when applying technical procedures?
- Applying the same technique in every situation without variation
- Adhering to established protocols while adapting to specific conditions (Correct answer)
- Using the fastest method available regardless of standards
- Following personal shortcuts developed through experience
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to established protocols as a foundation, with professional judgment to adapt appropriately to specific conditions. This balance ensures both consistency and effectiveness.
Question 76: What does `awk '{print $2}' file` output?
- The entire second line of the file
- The second field (column) of each line (Correct answer)
- The file content starting from line 2
- Lines that contain exactly 2 fields
Correct answer: The second field (column) of each line
In awk, $2 refers to the second whitespace-delimited field of each input record.
Question 77: A file is owned by user 'alice' and group 'staff'. User 'bob' is in the 'staff' group. The file has permissions rw-r-----. Can bob read the file?
- No, because bob is not the owner
- Yes, because others have no permission which defaults to group
- Yes, because bob is in the staff group which has read permission (Correct answer)
- No, because the file has no world-readable bits
Correct answer: Yes, because bob is in the staff group which has read permission
Bob belongs to the 'staff' group, which has read (r--) permission, so he can read the file.
Question 78: What nftables command lists all current rules across all tables and chains?
- nft show rules
- nft dump all
- nft display tables
- nft list ruleset (Correct answer)
Correct answer: nft list ruleset
'nft list ruleset' outputs the complete nftables configuration including all tables, chains, and rules.
Question 79: In Linux certification, what does redundancy in system design primarily provide?
- Lower initial cost
- Fault tolerance and high availability (Correct answer)
- Increased complexity
- Simplified maintenance
Correct answer: Fault tolerance and high availability
Redundancy provides fault tolerance by ensuring that if one component fails, backup components maintain system availability.
Question 80: How does the Linux body of knowledge relate to daily professional practice?
- It is theoretical and has limited practical application
- It is relevant only for academic research
- It only applies during certification exams
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 81: Which skill is most critical for effective user management?
- Technical expertise alone
- Individual work preferences
- Speed of decision-making
- Communication and stakeholder engagement (Correct answer)
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 82: Which file stores persistent iptables rules on RHEL/CentOS 7+ systems when using the iptables-services package?
- /etc/iptables/rules.v4
- /var/lib/iptables/rules
- /etc/sysconfig/iptables (Correct answer)
- /etc/firewall/iptables.conf
Correct answer: /etc/sysconfig/iptables
On RHEL/CentOS systems using iptables-services, rules are saved to /etc/sysconfig/iptables and loaded at boot.
Question 83: Which command would display all open network ports and the processes listening on them?
- ifconfig -a
- ip route show
- lsof -i -n
- netstat -tulpn (Correct answer)
Correct answer: netstat -tulpn
`netstat -tulpn` shows TCP/UDP listening ports with the process name/PID (requires root for all processes).
Question 84: Which LVM command removes a Physical Volume from a Volume Group?
- pvremove
- lvreduce
- vgchange -r
- vgreduce (Correct answer)
Correct answer: vgreduce
vgreduce removes one or more unused Physical Volumes from a Volume Group; pvremove is then used to remove the LVM metadata from the disk.
Question 85: What will `echo ${#myvar}` print if `myvar="hello"`?
- $myvar
- 0
- hello
- 5 (Correct answer)
Correct answer: 5
`${#varname}` expands to the length (number of characters) of the variable's value.
Question 86: What does the `-j DROP` option do in an iptables rule?
- Silently discards matching packets (Correct answer)
- Sends a rejection notice to the sender
- Logs the packet and drops it
- Forwards the packet to another chain
Correct answer: Silently discards matching packets
DROP silently discards packets without notifying the sender, unlike REJECT which sends an error message back.
Question 87: Which tool scans for open ports and services on a target host?
- ss
- mtr
- dig
- nmap (Correct answer)
Correct answer: nmap
`nmap` (Network Mapper) is a widely-used tool for port scanning, service detection, and network discovery.
Question 88: What is the recommended approach for handling errors in shell scripting?
- Suppress all error messages
- Let errors crash the application
- Implement structured error handling with meaningful messages (Correct answer)
- Log errors but never handle them
Correct answer: Implement structured error handling with meaningful messages
Structured error handling with meaningful messages helps diagnose problems quickly while maintaining application stability and user experience.
Question 89: Which nftables table type handles both IPv4 and IPv6 traffic in a single ruleset?
- inet (Correct answer)
- ip6
- bridge
- ip
Correct answer: inet
The inet table family handles both IPv4 and IPv6, allowing a single, unified ruleset instead of separate ip and ip6 tables.
Question 90: Which SSH configuration option disables password-based login, allowing only key-based authentication?
- AllowPassword false
- PasswordAuthentication no (Correct answer)
- DisablePassword yes
- AuthMethod key-only
Correct answer: PasswordAuthentication no
Setting PasswordAuthentication no in /etc/ssh/sshd_config forces clients to use key-based authentication.
CompTIA Linux+ (XK0-006)
CompTIA Linux+ certifies foundational Linux administration skills for IT professionals, covering system management, security, scripting/automation, and troubleshooting of Linux-based environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds