You want to watch new log entries for the sshd service as they arrive, on a systemd host. Which command does exactly that?

LPIC-1 Exam 102-500, objective 108. Essential system services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct journalctl -b sshd

Wrong. -b restricts output to a boot, not to a unit, and its optional argument is a boot id or offset. The trailing `sshd` is left as a positional argument, where journalctl expects a field match or a path to an executable, so the command errors out instead of following the service.

Correct journalctl -u sshd -f

Correct. -u (--unit) filters to the messages of one systemd unit and -f (--follow) keeps the command running and prints new entries as they are written, like tail -f.

Not correct journalctl -p sshd

Wrong. -p (--priority) filters by syslog severity and expects a level such as err or 3, not a unit name.

Not correct journalctl --since sshd

Wrong. --since expects a timestamp or a phrase such as "today" or "1 hour ago". It selects a time window, not a service.

Why

The journalctl filters most worth memorising: -u UNIT for one systemd unit, -f to follow live, -b for the current boot (-b -1 for the previous one), -p LEVEL for a severity and everything more urgent, -n N for the last N lines, --since and --until for a time window, and -k for kernel messages only. They combine freely, so `journalctl -u nginx -b -p err` is a legitimate query.

Where this comes from

Cited
LPI exam objective 108.2
What it says
Retrieve and filter journal entries with journalctl.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Essential system services

Practise LPIC-1 Exam 102-500