CompTIA Linux+ (XK0-006) — Questions and Answers
Question 1: What is the purpose of swap space in Linux?
- Provides overflow virtual memory on disk when RAM is full, and stores hibernation state (Correct answer)
- Stores temporary files during boot
- Caches frequently accessed files for faster access
- Provides a scratch area for file system repair tools
Correct answer: Provides overflow virtual memory on disk when RAM is full, and stores hibernation state
Swap extends the system's virtual memory by using disk space, and is used to store the contents of RAM during hibernation (suspend-to-disk).
Question 2: What does 'ls -l' display when a file has extended ACLs in addition to standard permissions?
- The word 'ACL' appended to the filename
- No visible difference in the output
- A '+' sign after the permission string (Correct answer)
- An 'A' prefix before the permissions
Correct answer: A '+' sign after the permission string
When a file has extended ACLs, ls -l shows a '+' at the end of the permission string to indicate additional access control entries exist.
Question 3: Which tool is used to audit Linux system calls made by a process for security analysis?
- ltrace
- lsof
- strace (Correct answer)
- auditd
Correct answer: strace
strace intercepts and records system calls made by a process, useful for identifying suspicious behavior.
Question 4: What does `pushd /tmp` do compared to `cd /tmp`?
- Changes to /tmp and deletes the previous directory
- Changes to /tmp and saves the previous directory on a stack (Correct answer)
- Changes to /tmp without updating $PWD
- Moves files to /tmp
Correct answer: Changes to /tmp and saves the previous directory on a stack
`pushd` saves the current directory onto a stack before changing, allowing `popd` to return to it later.
Question 5: Which statement BEST describes the relationship between Linux certification requirements and industry evolution?
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Requirements become less stringent over time
- Changes only occur when government mandates new requirements
- Certification requirements never change once established
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 6: What is the recommended response when a security incident is detected in an Linux environment?
- Follow the incident response plan: contain, eradicate, recover (Correct answer)
- Ignore minor incidents
- Delete all logs immediately
- Immediately shut down all systems
Correct answer: Follow the incident response plan: contain, eradicate, recover
Following a structured incident response plan ensures containment of the threat, eradication of the cause, and recovery to normal operations.
Question 7: What documentation is MOST critical to maintain for safety compliance in the Linux field?
- Employee vacation schedules
- Annual revenue reports
- Incident reports, training records, and inspection logs (Correct answer)
- Client marketing preferences
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation. They demonstrate compliance with safety regulations, track training completion, and provide evidence of systematic hazard management.
Question 8: What happens when you use `local varname` inside a bash function?
- Restricts the variable's scope to that function (Correct answer)
- Converts the variable to an array
- Makes the variable read-only
- Exports the variable to child processes
Correct answer: Restricts the variable's scope to that function
`local` limits a variable's visibility to the function (and its children), preventing pollution of the global scope.
Question 9: What happens when you run chmod u=rwx,g=rx,o= file.txt?
- Owner gets rwx, group gets r-x, others get no permissions (Correct answer)
- Only owner gets permissions; group and others are unchanged
- All users get rwx permissions
- Owner gets rwx, group gets rw-, others get r-x
Correct answer: Owner gets rwx, group gets r-x, others get no permissions
The = operator sets permissions exactly; u=rwx gives owner full access, g=rx gives group read+execute, and o= removes all permissions from others.
Question 10: Which command displays the current runlevel on a systemd-based Linux system?
- runlevel
- systemctl get-default
- init --status
- who -r (Correct answer)
Correct answer: who -r
The `who -r` command displays the current runlevel on both SysV and systemd systems.
Question 11: What does `resize2fs` do and when is it needed?
- Changes the block size of an existing ext filesystem
- Formats an ext filesystem to a specific size
- Resizes an ext2/3/4 filesystem to match a new partition size after the partition has been grown (Correct answer)
- Repairs inode size inconsistencies in ext filesystems
Correct answer: Resizes an ext2/3/4 filesystem to match a new partition size after the partition has been grown
After extending a partition (with fdisk/parted/LVM), resize2fs grows the ext filesystem to use the new available space.
Question 12: What command is used to erase or delete a file without receiving a confirmation message?
- Rm (Correct answer)
- Rm-f
- Remove
- Del
Correct answer: Rm
Explanation: <br> When rm is used only with the names of one or more files, it deletes them all without requesting the user's confirmation. Assuming that all three files are located in the current directory (i.e., the directory in which the user is now working), rm would immediately destroy the files called file1, file2, and file3:
Question 13: What is the primary purpose of the Linux Audit daemon (auditd)?
- Block unauthorized processes in real time
- Monitor network traffic for intrusions
- Scan files for malware signatures
- Record security-relevant system events to a tamper-evident log (Correct answer)
Correct answer: Record security-relevant system events to a tamper-evident log
auditd logs security events like file access, syscalls, and authentication attempts to /var/log/audit/audit.log.
Question 14: What does the `getent passwd username` command do?
- Lists all users with passwords set
- Retrieves the encrypted password for a user
- Fetches user account information from all configured name service databases (Correct answer)
- Displays password policy for the user
Correct answer: Fetches user account information from all configured name service databases
getent queries the Name Service Switch (NSS) databases including /etc/passwd, LDAP, and NIS for the specified user.
Question 15: Which line should appear at the very top of a bash script to specify the interpreter?
- # bash
- #!/bin/bash (Correct answer)
- #!bash
- // !/bin/bash
Correct answer: #!/bin/bash
The shebang `#!/bin/bash` tells the kernel which interpreter to use when the script is executed directly.
Question 16: What does `cut -d: -f1 /etc/passwd` do?
- Extracts the first colon-delimited field from each line (Correct answer)
- Counts the number of colons in /etc/passwd
- Removes the first field from /etc/passwd
- Displays only lines that start with a colon
Correct answer: Extracts the first colon-delimited field from each line
cut -d: sets the delimiter to colon and -f1 extracts the first field, which is the username in /etc/passwd.
Question 17: Which professional attribute is most valued in permissions within the Linux field?
- Prioritizing personal convenience
- Avoiding challenging situations
- Working in isolation
- Accountability and commitment to standards (Correct answer)
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 18: What does `grep -c "pattern" file` return?
- The file content with matching text colored
- The column number where each match begins
- The count of lines that match the pattern (Correct answer)
- A list of individual characters matching the pattern
Correct answer: The count of lines that match the pattern
grep -c suppresses normal output and prints only the total number of lines that match the given pattern.
Question 19: Which nftables hook corresponds to locally generated outbound traffic on a Linux host?
- output (Correct answer)
- input
- prerouting
- forward
Correct answer: output
The 'output' hook in nftables processes packets generated by local processes before they leave the network interface.
Question 20: What does the `mtr` command combine?
- arp and ip neigh results
- dig and nslookup queries
- ping and traceroute functionality (Correct answer)
- netstat and ss output
Correct answer: ping and traceroute functionality
`mtr` (Matt's Traceroute) combines continuous ping and traceroute into a real-time, interactive network diagnostic tool.
Question 21: How do you configure firewalld to add a service (e.g., http) to a zone permanently?
- firewall-cmd --zone=public --add-service=http --permanent (Correct answer)
- firewall-cmd --zone=public --service=http --permanent
- firewall-cmd --enable=http --zone=public
- firewall-cmd --add=http --zone=public --save
Correct answer: firewall-cmd --zone=public --add-service=http --permanent
The --add-service flag with a service name and --permanent persists the rule. firewalld has predefined service definitions for common services like http, https, ssh, etc.
Question 22: Which command would display the MAC address of the `eth0` interface?
- ip addr show eth0
- netstat -i eth0
- arp -i eth0
- ip link show eth0 (Correct answer)
Correct answer: ip link show eth0
`ip link show <interface>` displays link-layer information including the hardware (MAC) address of the interface.
Question 23: Which file contains SELinux boolean settings that affect network service behavior?
- The /etc/selinux/config file
- The /proc/sys/selinux/ directory
- The /etc/sysconfig/selinux file
- SELinux booleans managed with getsebool/setsebool commands, stored in kernel policy (Correct answer)
Correct answer: SELinux booleans managed with getsebool/setsebool commands, stored in kernel policy
SELinux booleans are part of the kernel policy and managed with getsebool -a (list all), setsebool (set), and semanage boolean (make permanent).
Question 24: In Linux practice, what is the CORRECT sequence when performing a technical procedure?
- Execute immediately and document only if issues arise
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute, then plan and review
- Document, execute, then plan
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows a systematic approach: plan the procedure, prepare necessary resources, execute according to standards, verify results meet specifications, and document the process and outcomes. This ensures quality and accountability.
Question 25: What does `sort -n` do differently from `sort` without flags?
- Sorts output in reverse order
- Sorts and removes duplicate lines
- Sorts by numeric value instead of lexicographically (Correct answer)
- Sorts while ignoring case
Correct answer: Sorts by numeric value instead of lexicographically
The -n flag causes sort to compare values as numbers, so '10' correctly sorts after '9' rather than before it.
Question 26: When a Linux professional encounters an unexpected result during a technical procedure, the FIRST action should be to:
- Continue the procedure and address it later
- Repeat the procedure from the beginning immediately
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Report the issue without any preliminary assessment
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess the situation when unexpected results occur is critical. This allows the professional to evaluate whether it is safe and appropriate to continue, and to determine if additional guidance or resources are needed.
Question 27: Which approach is MOST important for Linux professionals when applying technical procedures?
- Using the fastest method available regardless of standards
- Following personal shortcuts developed through experience
- Applying the same technique in every situation without variation
- Adhering to established protocols while adapting to specific conditions (Correct answer)
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to established protocols as a foundation, with professional judgment to adapt appropriately to specific conditions. This balance ensures both consistency and effectiveness.
Question 28: Which practice improves the security of shell scripting implementations?
- Input validation and principle of least privilege (Correct answer)
- Granting maximum permissions to all users
- Disabling all logging
- Using default credentials
Correct answer: Input validation and principle of least privilege
Input validation prevents injection attacks while the principle of least privilege limits the damage potential of any compromised component.
Question 29: Which nmap flag performs a SYN (stealth) scan without completing the TCP handshake?
- -sU
- -sS (Correct answer)
- -sA
- -sT
Correct answer: -sS
nmap -sS sends SYN packets and never completes the handshake, making the scan less likely to appear in connection logs.
Question 30: What does the `paste` command do?
- Concatenates files end-to-end like cat
- Copies clipboard content into a file
- Merges lines from multiple files side by side separated by tabs (Correct answer)
- Appends one file's content to the end of another
Correct answer: Merges lines from multiple files side by side separated by tabs
paste merges corresponding lines from multiple files horizontally, separating them with tab characters by default.
Question 31: Which log file records failed and successful sudo usage on most Linux distributions?
- /var/log/syslog
- /var/log/sudo.log
- /var/log/auth.log or /var/log/secure (Correct answer)
- /var/log/messages
Correct answer: /var/log/auth.log or /var/log/secure
Authentication events including sudo use are written to /var/log/auth.log (Debian-based) or /var/log/secure (RHEL-based).
Question 32: Which file must be edited to change the default shell for new users created with useradd?
- /etc/default/useradd (Correct answer)
- /etc/shells
- /etc/profile
- /etc/login.defs
Correct answer: /etc/default/useradd
/etc/default/useradd contains defaults like SHELL, HOME prefix, and SKEL path used by useradd.
Question 33: What is the function of the `bond0` interface type in Linux?
- Provides NAT bonding between private and public IPs
- Creates a virtual bridge between two subnets
- Aggregates multiple physical interfaces for redundancy or throughput (Correct answer)
- Bonds IPv4 and IPv6 stacks on a single interface
Correct answer: Aggregates multiple physical interfaces for redundancy or throughput
Linux bonding (bond0) combines multiple NICs into one logical interface, providing link aggregation for failover or increased bandwidth.
Question 34: Which bash arithmetic syntax correctly increments a variable `count`?
- $count++
- ((count++)) (Correct answer)
- count = count + 1
- count += 1
Correct answer: ((count++))
`(( ))` is bash's arithmetic evaluation context, where C-style expressions like `count++` are valid.
Question 35: Which command displays the routing table on a Linux system?
- arp -n
- netstat -r (Correct answer)
- ifconfig -r
- ip link show
Correct answer: netstat -r
The `netstat -r` command (or `ip route show`) displays the kernel IP routing table.
Question 36: What does the `-f` flag test for in `[ -f filename ]`?
- File exists and is a regular file (Correct answer)
- File exists and is not empty
- File exists and is a directory
- File exists and is executable
Correct answer: File exists and is a regular file
`-f` checks that the path exists and is a regular file (not a directory or device).
Question 37: Which SSH configuration option disables password-based login, allowing only key-based authentication?
- DisablePassword yes
- AuthMethod key-only
- PasswordAuthentication no (Correct answer)
- AllowPassword false
Correct answer: PasswordAuthentication no
Setting PasswordAuthentication no in /etc/ssh/sshd_config forces clients to use key-based authentication.
Question 38: How should Linux professionals handle technical procedures that have been updated or revised?
- Only apply updates to new cases or projects
- Continue using the original method if it still works
- Wait for mandatory enforcement before changing
- Review the updates, complete any required training, and implement the revised procedures (Correct answer)
Correct answer: Review the updates, complete any required training, and implement the revised procedures
When procedures are updated, professionals must review the changes, complete any required training to understand the rationale and new requirements, and implement the revised procedures in their practice. Continuing outdated methods risks non-compliance and suboptimal outcomes.
Question 39: What is 'port knocking' in the context of Linux firewall security?
- Forwarding traffic from one port to another
- Rate limiting port scans using iptables
- A technique where a specific sequence of connection attempts opens a firewall port (Correct answer)
- Scanning all ports to identify open services
Correct answer: A technique where a specific sequence of connection attempts opens a firewall port
Port knocking keeps ports closed until a predefined sequence of connection attempts is detected, then dynamically opens access.
Question 40: When systemd starts units in parallel, what mechanism does it use to determine dependency order?
- The order entries appear in /etc/rc.d/
- Alphabetical order of unit file names
- Unit file directives like After=, Before=, Requires=, and Wants= (Correct answer)
- Timestamps on unit files in /etc/systemd/system/
Correct answer: Unit file directives like After=, Before=, Requires=, and Wants=
systemd uses dependency directives (After=, Before=, Requires=, Wants=) in unit files to build a dependency graph for ordered parallel startup.
Question 41: Which command forces all users to change their passwords on their next login?
- chage --reset-all username
- usermod --force-reset username
- passwd --expire username
- chage -d 0 username (Correct answer)
Correct answer: chage -d 0 username
chage -d 0 sets the last password change date to epoch, forcing an immediate password change at next login.
Question 42: Which command updates the initramfs image on an Ubuntu/Debian system?
- update-initramfs -u (Correct answer)
- dracut --force
- grub-mkconfig
- mkinitrd
Correct answer: update-initramfs -u
`update-initramfs -u` rebuilds the initramfs for the current kernel on Debian-based systems.
Question 43: How should Linux professionals handle technical procedures that have been updated or revised?
- Continue using the original method if it still works
- Review the updates, complete any required training, and implement the revised procedures (Correct answer)
- Wait for mandatory enforcement before changing
- Only apply updates to new cases or projects
Correct answer: Review the updates, complete any required training, and implement the revised procedures
When procedures are updated, professionals must review the changes, complete any required training to understand the rationale and new requirements, and implement the revised procedures in their practice. Continuing outdated methods risks non-compliance and suboptimal outcomes.
Question 44: What role does calibration play in maintaining technical accuracy for Linux professionals?
- It only matters during formal inspections
- It is only necessary for new equipment
- It is an optional best practice for advanced professionals
- It ensures instruments and methods produce accurate, consistent results over time (Correct answer)
Correct answer: It ensures instruments and methods produce accurate, consistent results over time
Regular calibration ensures that instruments, tools, and methods continue to produce accurate and consistent results over time. Without calibration, measurement drift and equipment wear can lead to unreliable outcomes.
Question 45: What does the special variable `$?` represent in a shell script?
- The number of arguments passed
- The PID of the current shell
- The exit status of the last command (Correct answer)
- The name of the script
Correct answer: The exit status of the last command
`$?` holds the exit code of the most recently executed foreground command.
Question 46: Which signal is used to reload a daemon's configuration file without restarting it?
- SIGUSR1 (10)
- SIGHUP (1) (Correct answer)
- SIGKILL (9)
- SIGTERM (15)
Correct answer: SIGHUP (1)
SIGHUP (1) was originally a 'hangup' signal but many daemons handle it as a cue to reload their configuration files.
Question 47: What role does calibration play in maintaining technical accuracy for Linux professionals?
- It ensures instruments and methods produce accurate, consistent results over time (Correct answer)
- It is an optional best practice for advanced professionals
- It is only necessary for new equipment
- It only matters during formal inspections
Correct answer: It ensures instruments and methods produce accurate, consistent results over time
Regular calibration ensures that instruments, tools, and methods continue to produce accurate and consistent results over time. Without calibration, measurement drift and equipment wear can lead to unreliable outcomes.
Question 48: How does `while IFS= read -r line; do ...; done < file.txt` work?
- Reads file.txt line by line, stripping leading/trailing whitespace
- Appends each line to a variable named line
- Reads the file in binary mode
- Reads file.txt line by line, preserving whitespace and backslashes (Correct answer)
Correct answer: Reads file.txt line by line, preserving whitespace and backslashes
Setting `IFS=` prevents whitespace stripping and `-r` prevents backslash processing, giving raw lines.
Question 49: In Linux practice, what is the CORRECT sequence when performing a technical procedure?
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute, then plan and review
- Document, execute, then plan
- Execute immediately and document only if issues arise
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows a systematic approach: plan the procedure, prepare necessary resources, execute according to standards, verify results meet specifications, and document the process and outcomes. This ensures quality and accountability.
Question 50: What does `rpm --rebuilddb` do?
- Reinstalls all packages
- Removes corrupted packages
- Rebuilds the RPM database from installed package headers (Correct answer)
- Re-downloads all RPM package metadata
Correct answer: Rebuilds the RPM database from installed package headers
`rpm --rebuilddb` reconstructs the RPM database files from the installed package headers, used to fix a corrupted database.
Question 51: Which construct in bash properly iterates over all files in the current directory?
- foreach f in *; do echo $f; done
- loop f in *; do echo $f; done
- for f in *; do echo "$f"; done (Correct answer)
- for f in $(ls); do echo $f; done
Correct answer: for f in *; do echo "$f"; done
Using glob `*` directly is safer than parsing `ls` output, which breaks on filenames with spaces.
Question 52: What is the risk of having NOPASSWD in a sudoers entry?
- All users on the system gain root access
- The account password is deleted from /etc/shadow
- The user can run sudo commands without entering a password, bypassing authentication (Correct answer)
- Root login is enabled without a password
Correct answer: The user can run sudo commands without entering a password, bypassing authentication
NOPASSWD allows a user to invoke sudo without a password, which eliminates a key authentication checkpoint.
Question 53: What is the primary purpose of encryption in Linux security?
- To compress data
- To organize data more efficiently
- To make data transfer slower
- To protect data confidentiality during storage and transmission (Correct answer)
Correct answer: To protect data confidentiality during storage and transmission
Encryption protects data confidentiality by converting information into an unreadable format that can only be decoded with the proper key.
Question 54: Which bash feature allows `case "$var" in pattern) ... esac` to match multiple patterns?
- Separate them with ,
- Separate them with | (Correct answer)
- Separate them with ;
- Separate them with &&
Correct answer: Separate them with |
In a `case` statement, the `|` character separates alternative patterns for the same block.
Question 55: Which factor MOST significantly affects the quality of technical outcomes in Linux practice?
- The time of day the procedure is performed
- The brand of equipment being used
- The practitioner's training, preparation, and attention to detail (Correct answer)
- The speed at which procedures are completed
Correct answer: The practitioner's training, preparation, and attention to detail
The quality of technical outcomes depends primarily on the practitioner's level of training, thorough preparation, and careful attention to detail. While equipment matters, the professional's competence is the most significant factor.
Question 56: Which command displays the current SELinux enforcement mode?
- selinux -q
- getenforce (Correct answer)
- selinuxstatus
- sestatus --mode
Correct answer: getenforce
getenforce prints the current SELinux mode: Enforcing, Permissive, or Disabled.
Question 57: What does the `grep -i` flag do?
- Performs a case-insensitive search (Correct answer)
- Displays line numbers alongside matches
- Inverts the match to show non-matching lines
- Searches recursively through directories
Correct answer: Performs a case-insensitive search
The -i flag tells grep to ignore case differences when matching patterns, so 'Hello' matches 'hello'.
Question 58: Which `iptables` chain filters packets destined for the local system?
- OUTPUT
- INPUT (Correct answer)
- FORWARD
- PREROUTING
Correct answer: INPUT
The INPUT chain processes packets destined for the local machine's own network stack.
Question 59: What does the `lsblk` command show?
- Filesystem check results for block devices
- List of running processes using block devices
- Block device error logs
- Tree view of all block devices, their sizes, mount points, and types (Correct answer)
Correct answer: Tree view of all block devices, their sizes, mount points, and types
lsblk lists all block devices (disks, partitions, LVM volumes) in a tree structure showing relationships, sizes, and mount points.
Question 60: What does the `umask 022` setting mean for a newly created file?
- Files are created with permissions 022
- Files are created with permissions 755
- Files are created with permissions 600
- Files are created with permissions 644 (Correct answer)
Correct answer: Files are created with permissions 644
Default file permissions (666) minus umask (022) results in 644 (rw-r--r--) for new files.
Question 61: How do you append a line to a file inside a shell script without overwriting it?
- echo 'line' > file
- echo 'line' >> file (Correct answer)
- echo 'line' | file
- echo 'line' >| file
Correct answer: echo 'line' >> file
`>>` appends to a file; `>` truncates and overwrites.
Question 62: To clear the command prompt window, what command is used?
- Clear (Correct answer)
- Clearit
- Clr
- Clrwin
Correct answer: Clear
Explanation: <br> CLS Command Clears Command Prompt Screen You can type cls command line in Command Prompt window and push Enter button after opening Command Prompt on Windows 10 and entering numerous command lines on the screen. In Windows 10, this will clear the CMD screen. In the Command Prompt window, all previously input commands will be cleared.
Question 63: In Linux certification, what is the purpose of automated testing?
- To replace manual code review entirely
- To catch regressions and verify functionality continuously (Correct answer)
- To increase server costs
- To slow down development
Correct answer: To catch regressions and verify functionality continuously
Automated testing catches regressions early and verifies that functionality works as expected, providing confidence in code changes.
Question 64: What is the result of `echo "${var:-default}"` when `var` is unset?
- Prints nothing
- Causes an error
- Prints '$var'
- Prints 'default' (Correct answer)
Correct answer: Prints 'default'
`${var:-default}` expands to `default` if `var` is unset or empty, without modifying `var`.
Question 65: When a Linux professional encounters an unexpected result during a technical procedure, the FIRST action should be to:
- Report the issue without any preliminary assessment
- Continue the procedure and address it later
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Repeat the procedure from the beginning immediately
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess the situation when unexpected results occur is critical. This allows the professional to evaluate whether it is safe and appropriate to continue, and to determine if additional guidance or resources are needed.
Question 66: What is the effect of setting a user's shell to `/sbin/nologin`?
- Gives the user limited sudo access only
- Prevents the user from getting an interactive login shell (Correct answer)
- Deletes the user account on logout
- Restricts the user to the /sbin directory
Correct answer: Prevents the user from getting an interactive login shell
/sbin/nologin is a placeholder shell that prints a message and exits, preventing interactive logins while allowing other service authentications.
Question 67: Which command permanently mounts a filesystem by adding it to the appropriate configuration file?
- mount --permanent /dev/sdb1 /mnt/data
- systemctl enable mount@mnt-data
- mount --save /dev/sdb1 /mnt/data
- Edit /etc/fstab with the device, mount point, filesystem type, options, dump, and pass fields (Correct answer)
Correct answer: Edit /etc/fstab with the device, mount point, filesystem type, options, dump, and pass fields
/etc/fstab is the filesystem table where persistent mount configurations are defined; entries are processed at boot and by 'mount -a'.
Question 68: What does `$(command)` do in a shell script?
- Pipes command output to /dev/null
- Captures the command's stdout as a string (Correct answer)
- Runs the command in a subshell and discards output
- Executes the command in the background
Correct answer: Captures the command's stdout as a string
Command substitution `$(...)` replaces itself with the standard output of the enclosed command.
Question 69: Which nftables table type handles both IPv4 and IPv6 traffic in a single ruleset?
- ip6
- bridge
- inet (Correct answer)
- ip
Correct answer: inet
The inet table family handles both IPv4 and IPv6, allowing a single, unified ruleset instead of separate ip and ip6 tables.
Question 70: Which awk built-in variable defines the input field separator?
- FS (Correct answer)
- NF
- RS
- OFS
Correct answer: FS
FS (Field Separator) defines the delimiter awk uses to split each input record into fields; it defaults to whitespace.
Question 71: What firewall technique does 'iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE' implement?
- Packet marking
- Port forwarding
- IP masquerading (source NAT) (Correct answer)
- Destination NAT
Correct answer: IP masquerading (source NAT)
MASQUERADE is a form of SNAT that dynamically replaces the source IP with the outbound interface's IP, used for internet sharing.
Question 72: What is the definition of LAMP?
- The bus ID of a light-emitting USB device.
- The Linux Advanced Mode Programming Interface provides application developers with advanced capabilities.
- Linux, Apache, MySQL, PHP, and other programming languages in combination (Correct answer)
- LAMP stands for Lightweight Access Management Protocol, which synchronizes network permissions.
Correct answer: Linux, Apache, MySQL, PHP, and other programming languages in combination
Explanation: <br> LAMP stands for Linux as the operating system, Apache as the Web server, MySQL as the relational database management system, and PHP as the object-oriented scripting language in an open source Web development platform. (Perl or Python are sometimes used instead of PHP.).
Question 73: Which command counts lines, words, and bytes in a file?
- count
- len
- wc (Correct answer)
- size
Correct answer: wc
The wc (word count) command reports the number of lines, words, and bytes in a file by default.
Question 74: In iptables, what does the '-j RETURN' target do when used inside a user-defined chain?
- Returns to the calling chain and continues matching (Correct answer)
- Accepts the packet unconditionally
- Drops the packet immediately
- Logs the packet and drops it
Correct answer: Returns to the calling chain and continues matching
RETURN exits the current user-defined chain and resumes rule matching in the parent chain that invoked it.
Question 75: What does 'gpg --verify file.sig file' accomplish?
- Decrypts an encrypted file using the signature
- Generates a new GPG signature for the file
- Checks that the file's signature matches the signer's public key (Correct answer)
- Imports the signing key from the signature file
Correct answer: Checks that the file's signature matches the signer's public key
gpg --verify validates the detached signature file against the data file using the signer's public key in your keyring.
Question 76: In UEFI booting, where does the firmware look for the bootloader by default?
- /usr/lib/efi/grub.efi
- /boot/efi/EFI/BOOT/BOOTX64.EFI on the EFI System Partition (Correct answer)
- The first sector of the first hard disk
- /boot/grub2/grub.cfg
Correct answer: /boot/efi/EFI/BOOT/BOOTX64.EFI on the EFI System Partition
UEFI firmware searches the EFI System Partition for a fallback bootloader at EFI/BOOT/BOOTX64.EFI on x86-64 systems.
Question 77: In vim's normal mode, which key switches to insert mode placing the cursor before the current character?
- o
- a
- s
- i (Correct answer)
Correct answer: i
Pressing 'i' in vim's normal mode enters insert mode, positioning the cursor to insert text just before the current character.
Question 78: What is the purpose of TCP wrappers (hosts.allow / hosts.deny) in Linux?
- Route TCP traffic based on service type
- Monitor TCP connection counts per service
- Control access to services by matching hostnames or IPs against allow/deny lists (Correct answer)
- Encrypt TCP connections between hosts
Correct answer: Control access to services by matching hostnames or IPs against allow/deny lists
TCP wrappers use /etc/hosts.allow and /etc/hosts.deny to control which hosts can connect to services compiled with libwrap support.
Question 79: What is the primary purpose of the 'raw' table in iptables?
- Allows rules to exempt packets from connection tracking (Correct answer)
- Handles unencrypted plaintext traffic
- Processes traffic before NAT
- Stores raw packet captures
Correct answer: Allows rules to exempt packets from connection tracking
The raw table is processed before conntrack and is used with NOTRACK to exempt specific traffic from connection state tracking.
Question 80: Which factor MOST significantly affects the quality of technical outcomes in Linux practice?
- The time of day the procedure is performed
- The practitioner's training, preparation, and attention to detail (Correct answer)
- The speed at which procedures are completed
- The brand of equipment being used
Correct answer: The practitioner's training, preparation, and attention to detail
The quality of technical outcomes depends primarily on the practitioner's level of training, thorough preparation, and careful attention to detail. While equipment matters, the professional's competence is the most significant factor.
Question 81: What is the role of the journal in an ext3/ext4 filesystem?
- Backs up the superblock periodically
- Tracks inode allocation in real time
- Records metadata changes before they are committed, ensuring consistency after a crash (Correct answer)
- Stores a log of all file reads and writes for auditing
Correct answer: Records metadata changes before they are committed, ensuring consistency after a crash
The journal (write-ahead log) records pending metadata or data changes so the filesystem can replay or discard them after an unclean shutdown.
Question 82: Which approach is MOST important for Linux professionals when applying technical procedures?
- Applying the same technique in every situation without variation
- Using the fastest method available regardless of standards
- Following personal shortcuts developed through experience
- Adhering to established protocols while adapting to specific conditions (Correct answer)
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to established protocols as a foundation, with professional judgment to adapt appropriately to specific conditions. This balance ensures both consistency and effectiveness.
Question 83: What will `echo ${#myvar}` print if `myvar="hello"`?
- hello
- $myvar
- 0
- 5 (Correct answer)
Correct answer: 5
`${#varname}` expands to the length (number of characters) of the variable's value.
Question 84: What is the effect of running 'passwd -l username' on a Linux system?
- Deletes the user's password permanently
- Sets the account to expire immediately
- Forces a password change at next login
- Locks the user account by prefixing a '!' to the password hash (Correct answer)
Correct answer: Locks the user account by prefixing a '!' to the password hash
passwd -l locks an account by prepending '!' to the hashed password in /etc/shadow, preventing password-based login.
Question 85: What is the most effective approach to user management in the Linux field?
- Maintaining the status quo
- Reactive problem-solving
- Systematic planning and continuous improvement (Correct answer)
- Following competitors
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 86: What does the `lsblk` command display?
- List of blocked system calls
- Block device tree showing disks and partitions (Correct answer)
- Lock status of filesystem blocks
- List of bad blocks on a disk
Correct answer: Block device tree showing disks and partitions
`lsblk` lists block devices in a tree format showing disks, partitions, and their mount points.
Question 87: What is the purpose of the /etc/sudoers file?
- Store hashed passwords for sudo users
- Define which users can run commands as root or another user (Correct answer)
- Set password expiration policies
- Log all sudo command executions
Correct answer: Define which users can run commands as root or another user
/etc/sudoers specifies user and group privileges for running commands via sudo.
Question 88: Which command is used to list all current iptables rules in a Linux system?
- iptables -list
- iptables --show
- iptables -L (Correct answer)
- iptables -display
Correct answer: iptables -L
The `iptables -L` command lists all current firewall rules in all chains. Adding -v gives verbose output and -n prevents DNS lookups.
Question 89: What numeric UID range is typically reserved for system accounts on Linux?
- 1–99 only
- 500–999 only
- 0–499 or 0–999 depending on distro (Correct answer)
- 1000–1999
Correct answer: 0–499 or 0–999 depending on distro
System accounts typically use UIDs below 500 (Red Hat/CentOS) or below 1000 (Debian/Ubuntu), with regular users starting above that threshold.
Question 90: What does the 'umask 027' command do?
- Removes all permissions from new files
- Sets the maximum permission to 027
- New files get permissions 640 and new directories get 750 (Correct answer)
- Makes all new files executable
Correct answer: New files get permissions 640 and new directories get 750
umask 027 masks out write for group and all permissions for others, resulting in 640 for files and 750 for directories.
CompTIA Linux+ (XK0-006)
CompTIA Linux+ certifies foundational Linux administration skills for IT professionals, covering system management, security, scripting/automation, and troubleshooting of Linux-based environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds