You must find lines in /var/log/auth.log that mention root as a complete word, so that chroot and rootkit are not reported. Select the TWO commands that achieve this with GNU grep.
LPIC-1 Exam 101-500, objective 103. GNU and Unix commands medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Choose 2.
Correct grep -w root /var/log/auth.log
Correct. -w requires the match to be bounded on both sides by a non-word character or by the start or end of the line.
Correct grep '\<root\>' /var/log/auth.log
Correct. \< and \> are the GNU word-boundary escapes and express the same constraint inside the pattern itself.
Not correct grep root /var/log/auth.log
Wrong. A plain pattern matches anywhere in the line, so every occurrence inside a longer word is reported too.
Not correct grep -x root /var/log/auth.log
Wrong. -x requires the whole LINE to be exactly root, which no log line ever is.
Not correct grep -o root /var/log/auth.log
Wrong. -o changes only what is printed, cutting the output down to the matched text; the substring match itself is unchanged.
Why
Word matching constrains where a match may begin and end: a word constituent is a letter, digit or underscore, and -w insists that the characters on either side of the match are not word constituents. The pattern-level equivalents in GNU grep are \< and \> for the two boundaries and \b for either. Do not confuse -w (whole word) with -x (whole line) or with -o, which affects output rather than matching.
Where this comes from
- Cited
- manual page grep(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 103 and space the ones you get wrong.
More questions on this objective
- A user starts a new terminal window in a running graphical desktop session, which launches bash as an interactive shell that is NOT a login shell. Which file in the user's home directory does bash read in that case? machine-checked
- In bash, which history expansion re-runs the entire previous command line? machine-checked
- Which bash command prints the literal five characters $USER instead of the current user name? machine-checked
- You want /opt/bin searched for executables, after all the directories already in PATH, in the current bash session and in every command started from it. Which command does that? machine-checked
- There is a passwd manual page in section 1 (the command) and another in section 5 (the /etc/passwd file format). Which command opens the section 5 page? machine-checked
- Select the TWO true statements about shell variables and the environment in bash. machine-checked