While hunting for services to switch off, ss -ltn shows a socket listening on 0.0.0.0:8080 but gives you no idea which daemon owns it. Which invocation names the owning process?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct sudo ss -ltnp

Correct. -p (--processes) adds the process name and PID that holds each socket. It must be run with sufficient privilege, since an unprivileged user is only shown the processes it owns.

Not correct sudo ss -ltna

Wrong. -a adds non-listening sockets to the output, widening the list without ever naming a process.

Not correct sudo ss -ltne

Wrong. -e shows extended socket information such as the inode number and socket cookie. The inode can be traced back to a process by hand, but ss itself still prints no command name.

Not correct sudo ss -ltnr

Wrong, and it undoes part of the command. -r resolves numeric addresses back to host names, the opposite of what -n asked for, and says nothing about processes.

Why

The four options that make up a service audit with ss are -l for listening sockets, -t and -u to choose TCP or UDP, -n to keep ports and addresses numeric, and -p to attribute each socket to a process. The older net-tools equivalent is netstat -ltnp, and lsof -i :8080 answers the same question from the file-descriptor side.

Where this comes from

Cited
manual page ss(8)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500