Linux+ System Monitoring and Logging Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Linux+ System Monitoring and Logging flashcards as text
Which command would you use to watch changes to a file in real time, following log output as it is appended?
Answer: tail -f
tail -f continuously outputs new lines appended to a file, making it ideal for live log monitoring.
What is the primary purpose of the auditd daemon?
Answer: Recording security-relevant system calls and file access
auditd is the Linux Audit daemon that records security-relevant events like system calls, file accesses, and authentication attempts.
Which vmstat field indicates the number of processes waiting for run time (blocked)?
Answer: b
The 'b' field in vmstat shows the number of processes in uninterruptible sleep, typically waiting for I/O.
An administrator needs to search the systemd journal for all entries from the last 30 minutes. Which command accomplishes this?
Answer: journalctl --since '30 minutes ago'
The --since option accepts human-readable time expressions like '30 minutes ago' to filter journal entries.
Which file contains the current kernel ring buffer messages, equivalent to running dmesg?
Answer: /proc/kmsg
/proc/kmsg is the kernel's message ring buffer that dmesg reads from to display kernel messages.
What does the sar command stand for, and which package provides it on most Linux distributions?
Answer: System Activity Reporter, sysstat
sar stands for System Activity Reporter and is part of the sysstat package, collecting and reporting system performance data.
Which signal should be sent to syslogd or rsyslogd to make it re-read its configuration file without restarting?
Answer: SIGHUP
Sending SIGHUP to rsyslogd causes it to reload its configuration file and reopen log files without a full restart.