Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.)

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Choose 2.

Not correct last

Wrong for 'right now'. last reads /var/log/wtmp and prints a history of logins and logouts, including sessions that ended long ago and system reboot records. Its sibling lastb reads /var/log/btmp and prints failed login attempts.

Not correct lastlog

Wrong for 'right now'. lastlog reads the database /var/log/lastlog and prints the most recent login time for every account in the system, including accounts marked 'Never logged in'. It is a historical report, not a live one.

Correct who

Correct. who reads the utmp database of open sessions and lists the users currently logged in, with their terminal, login time and originating host.

Not correct id

Wrong. id prints the UID, primary GID and supplementary groups of a user, defaulting to the caller. It knows nothing about sessions.

Correct w

Correct. w lists the currently logged-in users like who, and adds uptime and load average in a header plus each session's idle time and the command it is currently running.

Why

Three databases underlie these tools. utmp holds currently open sessions and is what who, w and `users` report. wtmp is the append-only history of logins, logouts and reboots that last reads. btmp holds failed attempts and is read by lastb. /var/log/lastlog is a separate fixed-record file holding one 'most recent login' entry per UID, printed by lastlog. All are binary, so cat is useless on them.

Where this comes from

Cited
LPI exam objective 110.1
What it says
Determine which users are logged in and review login history.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500