XK0-005 — Frequently Asked Questions
Community-vetted answers to 10 common questions about this exam.
The primary debate centers on complexity versus functionality. While SysVinit uses simple, sequential shell scripts that are easy to read and debug, systemd offers parallel service startup, socket activation, cgroups integration, and journaling. Critics argue systemd violates the Unix philosophy of 'do one thing well' by becoming a monolithic suite, while proponents emphasize its necessity for managing modern containerized and cloud-native workloads efficiently. For the XK0-005 exam, understanding both systemctl commands and legacy /etc/init.d/ scripts is required, but real-world discussions focus on whether systemd's feature set justifies its steep learning curve and potential security attack surface.
SELinux (used in RHEL/Fedora) provides fine-grained, label-based MAC with extensive policy modules but has a reputation for being difficult to configure and troubleshoot, often leading admins to disable it improperly. AppArmor (used in Debian/Ubuntu) uses path-based profiles that are simpler to write and maintain but offer less granular control over object interactions. The debate hinges on security depth versus operational overhead: SELinux is preferred for high-security compliance (FIPS, STIG) despite its complexity, while AppArmor is favored for developer-friendly environments where rapid deployment matters. XK0-005 candidates must know how to manage both (semanage, aa-status) and interpret denial logs.
Btrfs advocates highlight built-in snapshots, subvolumes, checksumming, and RAID capabilities that eliminate the need for separate LVM/mdadm layers. Critics point to historical instability in RAID5/6 modes, slower metadata performance, and higher memory usage compared to mature filesystems like ext4/XFS. Ext4 remains the default for reliability and simplicity; XFS excels at large file handling and scalability. The consensus for XK0-005 is that Btrfs is excellent for desktops/backups but requires careful validation for critical production databases. Exam questions test knowledge of btrfs subvolume, snapper, and repair tools alongside traditional fsck and xfs_repair.
Docker uses a daemon-centric architecture requiring root privileges, creating a single point of failure and security risk. Podman is daemonless, rootless by default, and OCI-compliant, aligning better with systemd and security best practices. However, Docker’s ecosystem maturity, documentation, and third-party tooling support remain unmatched. The debate reflects industry transition: enterprises adopting rootless containers prefer Podman, while developers and CI/CD pipelines still rely heavily on Docker. XK0-005 covers both, emphasizing understanding of OCI standards, image registries, and the ability to switch between docker and podman CLI syntax seamlessly.
Ansible’s agentless, YAML-based playbook model lowers entry barriers and suits ad-hoc tasks and immutable infrastructure. Puppet/Chef use agent-based, declarative DSLs better suited for continuous enforcement and complex state management at scale. The debate centers on simplicity versus precision: Ansible wins for quick wins and hybrid teams; Puppet/Chef dominate regulated environments requiring audit trails and drift correction. For XK0-005, Ansible is heavily emphasized due to its Red Hat alignment and relevance to modern DevOps, but candidates should understand basic Puppet/Chef concepts and recognize when each tool is appropriate based on organizational needs.
Common issues include loading incompatible modules after kernel updates, missing dependencies causing boot failures, and blacklisting conflicts. Admins debate manual modprobe/insmod usage versus automated dependency resolution via depmod. Secure Boot environments add complexity by requiring signed modules. Online forums stress verifying module parameters in /etc/modprobe.d/ and using dkms for out-of-tree drivers. For the exam, candidates must master lsmod, modinfo, rmmod, and understand /proc/modules and dmesg output to diagnose hardware/driver issues without relying solely on GUI tools.
nftables replaces iptables/ip6tables/arptables with a unified framework offering better performance, atomic rule updates, and expressive syntax. However, iptables remains deeply embedded in tutorials, legacy scripts, and muscle memory. The debate involves migration pain versus long-term benefits: nftables is the future, but iptables compatibility layer (iptables-nft) eases transition. For XK0-005, candidates must know both syntaxes, understand translation tools (iptables-translate), and recognize that many exam scenarios still reference iptables chains/rules while expecting awareness of nftables as the successor. Practical labs should cover both to avoid real-world gaps.
LVM offers flexible volume management, snapshots, and thin provisioning within the Linux ecosystem, making it ideal for dynamic server environments. ZFS combines filesystem and volume manager with advanced data integrity features but has licensing concerns and higher resource demands. Standard partitioning is simple but inflexible. Debates center on use cases: LVM for general-purpose servers, ZFS for NAS/storage appliances, standard partitions for embedded/minimal installs. XK0-005 focuses heavily on LVM (lvcreate, vgextend, pvmove) and basic partitioning (fdisk, parted), with ZFS mentioned conceptually. Candidates should practice resizing volumes online and recovering from PV failures.
Best practices include disabling root login, enforcing key-based auth, using fail2ban, and restricting ciphers/KEX algorithms. However, overly strict policies break automation, hinder emergency access, and frustrate users. Debates involve MFA adoption (TOTP vs. FIDO2), password policy enforcement (pam_pwquality vs. pam_unix), and jump host architectures. For XK0-005, candidates must configure sshd_config securely, manage SSH keys/agents, understand PAM stack ordering, and implement sudoers with least privilege. Real-world discussions emphasize documenting exceptions and testing changes in staging to avoid locking out legitimate users during hardening.
RPM/dnf offers robust dependency resolution, modular repositories, and transaction history rollback, favored in enterprise RHEL environments. APT/aptitude provides faster operations, simpler syntax, and vast community repositories, dominant in Debian/Ubuntu ecosystems. Debates include metadata freshness vs. speed, plugin extensibility, and handling of third-party repos. For XK0-005, candidates must proficiently use both dnf/yum and apt/dpkg, understand repo configuration (/etc/yum.repos.d/, /etc/apt/sources.list), GPG key management, and package querying (rpm -q, dpkg -l). Exam scenarios often require cross-distro troubleshooting, so fluency in both ecosystems is non-negotiable.
← Back to CompTIA Linux+ XK0-005 Exam Questions & Knowledge Points