An administrator runs `ss -tulpn`. What does the `p` in that flag cluster add to the output?

LPIC-1 Exam 102-500, objective 109. Networking fundamentals medium

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct It prints the protocol name of each socket

Wrong. The protocol is already implied by -t (TCP) and -u (UDP) and shown in the first column. No ss flag is needed for it.

Correct It shows the process name and PID that owns each socket

Correct. -p (--processes) attaches the owning process to each socket line. You need root to see processes belonging to other users; without privileges the column is mostly blank.

Not correct It restricts the listing to sockets in the LISTEN state

Wrong. That is -l (--listening). -l is the flag that turns this command into a listening-ports report.

Not correct It resolves numeric ports to service names from /etc/services

Wrong, and backwards. ss resolves names by default; -n (--numeric) is the flag that suppresses resolution and shows raw numbers.

Why

In `ss -tulpn`: -t TCP, -u UDP, -l listening sockets only, -p owning process, -n numeric (no port or host name resolution). ss ships with iproute2 and is the modern replacement for netstat, whose closest equivalent is `netstat -tulpn`.

Where this comes from

Cited
manual page ss(8)

Practise this

Reading one question is not practice. The trainer will draw a set from objective 109 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500