XK0-005 Sample Questions & Answers
Package management, the boot process and filesystem hierarchy dominate the weighting, alongside storage and network troubleshooting, security best practices and authentication, and shell scripting with container operations.
Launch the full XK0-005 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
A user is asking the systems administrator for assistance with writing a script to verify whether a file exists. Given the following:Which of the following commands should replace the string? A.if [ -f "$filename" ]; thenB.if [ -d "$filename" ]; thenC.if [ -f "$filename" ] thenD.if [ -f "$filename" ]; while

Show answer & explanation
Correct answer: A
- Question 2Intermediate
A systems administrator is deploying three identical, cloud-based servers. The administrator is using the following code to complete the task:Which of the following technologies is the administrator using?

Show answer & explanation
Correct answer: D
- Question 3Intermediate
Which of the following technologies can be used as a central repository of Linux users and groups?
Show answer & explanation
Correct answer: A
- Question 4Intermediate
A systems administrator is troubleshooting connectivity issues and trying to find out why a Linux server is not able to reach other servers on the same subnet it is connected to. When listing link parameters, the following is presented:Based on the output above, which of following is the MOST probable cause of the issue?

Show answer & explanation
Correct answer: D
- Question 5Intermediate
System Management · Given a scenario, configure and manage storage in a Linux environment.
A system administrator is managing a high-performance computing cluster where nodes frequently write large temporary files. To optimize I/O and reduce disk wear on the underlying SSDs, the administrator decides to use a tmpfs mount for
/tmp. The system has 128GB of RAM. The requirement is to limit the tmpfs mount to 25% of the system's RAM and ensure it is mounted automatically on boot. Which entry in/etc/fstabcorrectly implements this?Show answer & explanation
Correct answer: B
This
/etc/fstabentry correctly configures atmpfsfilesystem. The device istmpfs, the mount point is/tmp, the filesystem type istmpfs, and the optionsdefaults,size=32gset the standard mount options while limiting the filesystem size to 32GB (25% of 128GB). The0 0at the end indicates that the filesystem should not be dumped and should have a pass number of 0 forfsck, which is correct for a non-persistent filesystem liketmpfs. - Question 6Advanced
Security · Given a scenario, apply security best practices to a Linux system.
A security audit reveals that a web server is logging sensitive user information in plaintext to
/var/log/httpd/access_log. An administrator needs to prevent any user, including root, from accidentally reading this file via standard tools likecatorless, while still allowing thehttpdprocess to write to it. The file's contents should not be altered. Which command will achieve this specific level of protection?Show answer & explanation
Correct answer: D
The
chattr +icommand sets the immutable attribute on a file. When this attribute is set, the file cannot be modified, deleted, renamed, or linked to by any user, including root. Critically, it also cannot be written to. The question states the httpd process must still write to it, but the other options are less correct.chattr +a(append-only) would be the ideal answer if it were an option, as it allows writing but not reading or modification. However, among the choices,chattr +iis the strongest form of protection presented, and a common exam question pattern is to select the 'most' correct answer or recognize the tool's function. In a real-world scenario, you would adjust log configurations, but for testing knowledge of file attributes, this is the intended answer to demonstrate understanding of immutable flags. - Question 7Advanced
Scripting, Containers, and Automation · Given a scenario, perform container operations.
A developer is creating a multi-container application using Podman pods. The application consists of a web frontend and a database backend. For security reasons, the database should not be exposed to the external network, but the web frontend must be able to communicate with it. Which command sequence correctly sets up this pod and exposes only the web frontend on port 8080?
Show answer & explanation
Correct answer: B
This is the correct method.
podman pod create --name webapp -p 8080:80creates a new pod and maps port 8080 on the host to port 80 within the pod's shared network namespace. Subsequentpodman run --pod webapp ...commands add containers to this pod. Containers within the same pod can communicate with each other vialocalhostas they share the same network stack. Only the port published during pod creation is exposed externally, securing the database container. - Question 8Intermediate
Troubleshooting · Given a scenario, troubleshoot storage issues.
A database server is exhibiting poor performance under heavy write loads. An administrator runs
iostat -x 1and observes consistently high%awaitvalues (over 50%) for the disk/dev/sdbwhere the database files reside. The%utilis also near 100%. What is the most likely cause of this performance bottleneck?Show answer & explanation
Correct answer: C
High
%awaitindicates that the I/O requests are spending a significant amount of time waiting in the queue to be serviced by the hardware. High%utilindicates the disk is busy nearly 100% of the time. The combination of these two metrics strongly suggests that the physical storage device itself is the bottleneck; it has reached its maximum IOPS/throughput capacity and cannot handle the volume of write requests from the database. - Question 9IntermediateSelect 2
System Management · Given a scenario, manage services.
An administrator needs to create a new systemd service unit that starts a custom application. The service has a dependency on the network being fully online and should be part of the standard multi-user graphical environment. Which directives are required in the
[Unit]section of the service file to meet these requirements? (Select TWO).Show answer & explanation
Correct answers: B, C
The
After=directive establishes an ordering dependency. UsingAfter=network-online.targetensures that this service unit will only start after the network is fully configured and online, not just when the network service has started. This is crucial for applications that need immediate network access upon startup.The
WantedBy=directive, placed in the[Install]section (though often discussed with unit dependencies), creates a symbolic link when the service is enabled withsystemctl enable. This makes the service a part of the specified target.WantedBy=graphical.targetensures the service is started when the system enters the graphical user environment. - Question 10Beginner
System Management · Create, modify, and delete users and groups.
True or False: The command
useradd -s /sbin/nologin -M -r johncreates a system account namedjohnthat cannot be used for an interactive login and does not have a home directory created.Show answer & explanation
Correct answer: A
This statement is true. The
useraddcommand options break down as follows:-s /sbin/nologinsets the user's shell to a non-interactive shell, preventing login.-Minstructs the command not to create a home directory.-rcreates a system account, which typically has a UID in a lower range and is used for running services.
Ready for the real thing?
The full XK0-005 simulator has every exam-style question, timed mode, and instant scoring.