Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.
Start practicing
Security — choose a session length
Free · No account required
Domain overview
The Security domain of CompTIA Linux+ XK0-006 covers host hardening and access control on Linux systems. Expect scenario questions on SELinux and AppArmor modes, user account and password aging with useradd, passwd, and chage, file permissions and ownership, sudo configuration, and SSH and firewall basics. Items ask you to pick the exact command or file that produces a described state.
Exam objectives
Switching AppArmor profiles between complain and enforce mode with aa-complain and aa-enforce
Reading SELinux state with getenforce and sestatus, and adjusting it via setenforce or config files
Creating users with useradd, setting shells and home directories, and forcing password changes with chage
Managing sudo privileges, file ownership and permissions, and SSH or firewall access rules
Confusing SELinux and AppArmor tooling, or assuming setenforce changes persist across reboots when it only alters runtime mode
Using usermod or passwd when the task actually requires chage to expire a password or set aging policy
Forgetting that useradd alone does not set a password, so the account stays locked until passwd or chpasswd runs
Click any question to see the full explanation and answer options, or start a focused practice session above.
A Linux administrator needs to add a new user named 'jdoe' with a home directory and a bash shell. Which command accomplishes this?
2A security audit reveals that users can change their password without meeting complexity requirements. Which PAM module should be configured to enforce password complexity?
3An administrator wants to allow the user 'ops' to run only the command '/usr/bin/systemctl restart httpd' via sudo on a specific host 'webserver'. Which /etc/sudoers entry is correct?
4An AppArmor profile for a web server is in complain mode. After testing, the administrator wants to enforce the profile. Which command accomplishes this?
5An administrator is hardening SSH and wants to disable root login and only allow users in the 'sshusers' group. Which two directives should be set in /etc/ssh/sshd_config?
6An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?
7A security policy requires that user passwords must be changed every 60 days, and users should be warned 7 days before expiration. Which two chage commands set these requirements for user 'jsmith'? (Choose TWO.)
8An administrator is configuring iptables on a server. The requirements are: allow incoming SSH (port 22) from the 192.168.1.0/24 network, drop all other incoming traffic, and allow all outgoing traffic. Which three iptables rules achieve this? (Choose THREE.)
9An administrator wants to restrict SSH access to only users in the 'sshusers' group. Which configuration directive should be added to /etc/ssh/sshd_config?
10A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?
11A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.
12An administrator needs to configure SELinux to allow the Apache HTTP server to connect to a database server. Which SELinux boolean should be enabled?
13A file named 'webapp.conf' is being served by Apache but users get a 'Permission denied' error. The SELinux context of the file is 'unconfined_u:object_r:admin_home_t:s0'. What is the most appropriate command to fix the SELinux context?
14An administrator notices repeated failed login attempts in /var/log/secure. The company policy requires account lockout after 5 failed attempts within 15 minutes. Which PAM module and configuration can enforce this?
15A system administrator is hardening SSH and needs to disable root login and password authentication. Which two directives should be set in /etc/ssh/sshd_config?
16Which command can be used to generate an SSH key pair for user authentication?
17A Linux engineer needs to restrict resource usage for users in the 'developers' group. Which TWO files or commands can be used to set ulimit values?
18Which THREE are valid SELinux modes?
19Which file contains user password hashes and aging information on a Linux system?
20A security analyst wants to ensure that users cannot change their password more than once every 7 days. Which command and option should be used to enforce this policy for user 'jsmith'?
21A system administrator configures PAM to enforce account lockout after 3 failed login attempts. Which PAM module should be used?
22To limit the number of processes a user can create, which file should be configured?
23An administrator needs to view all current nftables rules. Which command should be used?
24SELinux is currently in enforcing mode. A service is being blocked by SELinux. Which command can analyze the audit log and suggest the minimum policy changes to allow the service?
25To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?
26Which log file typically records authentication failures and successes on a Debian-based system?
27An administrator wants to generate a self-signed certificate and private key for testing. Which command creates both in one step?
28A security administrator is reviewing SSH configuration. Which TWO settings enhance security by limiting authentication attempts and preventing password-based logins? (Choose two.)
29After configuring AppArmor, an administrator wants to verify the status of all profiles and switch a profile from complain to enforce mode. Which TWO commands are appropriate? (Choose two.)
30A Linux administrator needs to prevent the root user from logging in via SSH. Which directive should be set in /etc/ssh/sshd_config to accomplish this?
31A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?
32A Linux administrator is troubleshooting a service that fails to start. The audit.log shows an AVC denial related to the httpd_t domain. The administrator wants to see the full denial message and generate a policy to allow the access. Which two commands should be used in conjunction?
33A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?
34An administrator wants to enforce an account lockout policy after five failed login attempts on a Linux system. Which PAM module should be added to the authentication stack?
35A system administrator needs to add an iptables rule to drop incoming TCP traffic on port 22 (SSH) from the IP address 10.0.0.100. Which command should be used?
36A security analyst needs to see a list of failed login attempts on a Linux system. Which command displays this information from the /var/log/btmp log?
37An administrator wants to ensure that only users in the 'wheel' group can use the sudo command. Which directive in /etc/sudoers enables this?
38A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?
39A system administrator wants to enforce a password policy requiring a minimum length of 12 characters, at least one uppercase letter, and one digit. Which PAM module should be configured?
40A security audit reveals that an SELinux boolean 'httpd_can_network_connect' is currently off, but a web application requires Apache to connect to a database server. Which command should the administrator use to enable this boolean persistently?
41An administrator needs to prevent a specific user 'bob' from logging in via SSH while allowing other users. Which configuration directive should be added to /etc/ssh/sshd_config?
42A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?
43An administrator needs to generate a self-signed certificate and private key for a web server. Which openssl command accomplishes this?
44Which file contains the hashed passwords and password aging information for user accounts?
45A security policy requires that system logs be rotated weekly and kept for 4 weeks. Which configuration file should be modified to achieve this for /var/log/syslog?
46An administrator is troubleshooting an AppArmor profile that is blocking a custom application. They want to set the profile to complain mode to gather violations without enforcing. Which command should they use?
47A Linux administrator needs to configure sudo access for members of the 'wheel' group to run any command. Which two steps are required? (Choose TWO.)
48An administrator wants to harden SSH access by implementing the following: disallow root login, disable password authentication, and limit the number of authentication attempts. Which three configuration directives should be set in /etc/ssh/sshd_config? (Choose THREE.)
49A security audit reveals that a service is running with an incorrect SELinux context. Which two commands can be used to relabel the file or directory to the correct context? (Choose TWO.)
50A Linux administrator needs to add a new user named 'jdoe' with a home directory and bash shell. Which command accomplishes this?
51An administrator wants to force a password change for user 'alice' on next login. Which command is appropriate?
52A system administrator needs to configure sudo so that members of the 'wheel' group can execute any command without a password. Which line should be added to /etc/sudoers (using visudo)?
53A security analyst notices repeated failed login attempts on a Linux server. They want to lock the account after 3 failed attempts using PAM. Which PAM module should be configured in /etc/pam.d/sshd or /etc/pam.d/system-auth?
54A web server running on port 8080 must be accessible from external networks. The system uses firewalld. Which command opens port 8080/tcp permanently in the default zone?
55A Linux server has SELinux enforcing and a custom application needs to write to /var/log/app.log. The audit log shows 'avc: denied { write } for pid=1234'. After verifying that the application runs in the correct domain, which command should be used to allow the write access by generating a policy module?
56An administrator needs to ensure that only users from the 'ops' group can SSH into a server. Which configuration in /etc/ssh/sshd_config accomplishes this?
57A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?
58Which command displays the current SELinux mode?
59An administrator needs to generate a self-signed certificate and private key for an internal web server. Which OpenSSL command creates both in one step?
60A system administrator wants to limit the number of simultaneous logins for a user to 2. Which file and parameter should be configured?
61An administrator needs to harden SSH access. Which TWO settings in /etc/ssh/sshd_config are recommended to improve security? (Choose two.)
62A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)
63A Linux administrator wants to prevent users from reusing their last five passwords. Which PAM module should be configured?
64A technician needs to ensure a service can listen on TCP port 8443 using firewalld. Which command permanently adds the port to the default zone?
65An administrator needs to generate a self-signed certificate valid for 365 days with a 2048-bit RSA key. Which OpenSSL command correctly creates both the private key and certificate in one step?
66Which file contains the password aging information such as minimum and maximum days between password changes?
67A security team wants to restrict SSH access to only users in the 'sshusers' group. Which configuration line in /etc/ssh/sshd_config achieves this?
68An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?
69A security audit has identified that several users have excessive sudo privileges. The administrator needs to review and modify sudo access. Which two files or commands would be used? (Choose TWO.)
70A Linux administrator needs to add a new user named 'jdoe' with a home directory and default shell /bin/bash. Which command should be used?
71A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?
72An administrator notices that a custom application uses port 8443/TCP. To allow external access, which firewalld command permanently opens this port in the default zone?
73Which of the following correctly describes the purpose of the /etc/shadow file?
74An administrator configures /etc/ssh/sshd_config with the following settings: PermitRootLogin no, PasswordAuthentication no, AllowUsers alice bob, MaxAuthTries 2. After restarting sshd, which of the following is true?
75A security audit reveals that the system's PAM configuration does not enforce password complexity. Which PAM module and configuration line should be added to /etc/pam.d/common-password to require at least one uppercase letter, one digit, and a minimum length of 12 characters?
76An administrator runs 'auditctl -w /etc/passwd -p wa -k passwd_changes' to monitor changes to /etc/passwd. Which command should be used to search the audit log for all events related to this watch?
77A Linux engineer needs to harden SSH access. Which TWO of the following settings should be configured in /etc/ssh/sshd_config to enhance security? (Select TWO.)
78A security analyst is investigating a potential breach and needs to examine user login history. Which THREE commands or log files provide information about user logins? (Select THREE.)
79A Linux administrator wants to harden a server against brute-force attacks. They decide to use fail2ban to monitor SSH authentication failures. After installing and enabling the fail2ban service, they need to verify that the SSH jail is active and correctly configured. Which command should they use to check the current status of the sshd jail?
80A Linux administrator needs to grant the user 'jsmith' the ability to restart the httpd service without entering a password, while preventing all other sudo commands. The administrator creates the file /etc/sudoers.d/jsmith with the line: jsmith ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd. After saving the file, jsmith reports that sudo still prompts for a password. Which command should the administrator run to diagnose the issue?
81A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?
82A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?
83A security engineer must ensure that a new SSH host key is generated using the Ed25519 algorithm and stored in the default location. Which command accomplishes this?
84A Linux administrator needs to configure the system so that all users must use a minimum password length of 12 characters. The administrator edits /etc/security/pwquality.conf. Which line should be added or modified to enforce this requirement?
85A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?
86A junior administrator needs to check whether a user account named 'bob' is locked and view the password aging information. Which command should be used?
87A Linux administrator wants to allow the web server (httpd) to bind to a non-standard port, TCP 8080, without disabling SELinux. The system is running SELinux in enforcing mode. Which command should the administrator run to permanently allow httpd to listen on TCP port 8080?
88A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)
89A Linux administrator is implementing mandatory access control using AppArmor on an Ubuntu server. A custom web application profile is loaded in enforce mode, but the application is failing to write to /var/log/myapp/. The administrator wants to temporarily switch the profile to complain mode to diagnose the issue without disabling AppArmor entirely. Which command should be used?
90A security administrator needs to configure a Linux server so that all users must use a password of at least 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these requirements?
91A security administrator is hardening a Linux server and wants to verify that the SSH daemon is configured to disallow direct root logins. The administrator has already edited /etc/ssh/sshd_config and set PermitRootLogin no. Which command should the administrator run to ensure the SSH daemon reloads the configuration without terminating existing SSH sessions?
92A security team wants to harden a Linux server against unauthorized access. They need to restrict which users can authenticate via SSH and ensure that only key-based authentication is allowed for a specific group. Which TWO actions should the administrator take? (Choose two.)
93A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)
94A Linux administrator is configuring a server that must meet strict security guidelines. The server uses firewalld and should drop all incoming traffic on the public zone by default, but allow outgoing SSH connections initiated by the server itself to a remote management host. Which firewalld configuration should the administrator apply?
95A compliance auditor requires that a Linux server's /home directory be mounted with options that prevent users from executing setuid binaries stored there and from creating device files. The administrator is editing /etc/fstab for the /home entry. Which TWO mount options should be added to meet these requirements? (Choose two.)
96A Linux administrator is configuring a server to use a centralized authentication service. The security policy requires that user credentials are never sent in clear text and that the authentication traffic is encrypted. The administrator decides to use LDAP with TLS. Which command should be used to verify that the LDAP server's certificate is valid and that the TLS handshake succeeds?
97A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?
98A Linux administrator is configuring a system to use a centralized authentication service. The requirement is that if the central server is unreachable, users should still be able to log in using cached credentials. Which PAM module should be configured to provide this functionality?
99A Linux administrator needs to ensure that user passwords meet a minimum length requirement of 12 characters. The system uses PAM and the pam_pwquality module. Which file should the administrator edit to set the minlen parameter?
100A Linux administrator needs to ensure that all user passwords meet a minimum length of 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these password complexity requirements?
101A Linux administrator is configuring a server to use firewalld. The administrator wants to allow incoming traffic on TCP port 8080 only from the 192.168.1.0/24 subnet, while denying it from all other sources, without affecting other services. Which firewalld command should the administrator use to achieve this?
102A Linux administrator is configuring an SSH server to use certificate-based authentication. The administrator has generated a CA key pair and wants to sign a user's public key. Which command should be used to sign the user's public key with the CA and produce a certificate?
103A Linux server is configured with an IPsec VPN using strongSwan. The administrator needs to verify that the VPN tunnel is active and that traffic is being encrypted. Which command should be used to display the current status of the IPsec security associations?
104A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?
105A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)
106A Linux administrator needs to grant a user named 'bob' the ability to run the /usr/bin/systemctl command as root without being prompted for a password. Which entry should be added to the sudoers file to accomplish this?
107A Linux administrator needs to grant a user the ability to run a specific command as root without being prompted for a password, while restricting all other commands. Which file should be edited to configure this using sudo?
108A Linux server hosts a web application that must be able to bind to TCP port 443. The administrator has already installed the application and configured it to listen on 443. However, when the service starts, it fails with a 'Permission denied' error. The administrator confirms that no other process is using port 443 and that the service runs as the non-root user 'webapp'. Which command should the administrator use to grant the necessary capability to the service binary without giving it full root privileges?
109A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?
Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.
The Courseiva XK0-006 question bank contains 109 questions in the Security domain, covering the 18% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included