hardMultiple Choice
XK0-006 Practice Question: A company uses a Linux server running Ubuntu…
A company uses a Linux server running Ubuntu 22.04 LTS as a file server to share documents via Samba. The server has been in operation for over a year without issues. Following a routine system update that included kernel patches and updated Samba packages, users began reporting that they could no longer access any shared folders. The administrator verifies that the smbd and nmbd services are running and have not failed. The Samba configuration has not been changed recently. The server uses ufw as its firewall. When the administrator runs 'ufw status', the output shows that only SSH (port 22) is allowed. The administrator checks for SELinux but finds it is not installed; however, AppArmor is active and the smbd profile is in enforce mode. The administrator examines the AppArmor logs and finds no denials related to smbd. Which of the following is the most likely reason for the connectivity failure?
⚠ Common exam trap
The trap here is that candidates may focus on AppArmor or SELinux because they are security modules, but the absence of denials in AppArmor logs and the explicit ufw output showing only SSH allowed points directly to the firewall as the culprit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall is blocking Samba ports 137, 138, 139, and 445.
The firewall (ufw) is only allowing SSH (port 22), which means Samba ports 137/138 (NetBIOS), 139 (SMB over NetBIOS), and 445 (SMB over TCP) are blocked. Since the smbd and nmbd services are running and AppArmor shows no denials, the most likely cause is that the firewall rules were reset or not updated after the system update, preventing Samba traffic from reaching the server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall is blocking Samba ports 137, 138, 139, and 445.
Why this is correct
ufw permits only port 22, so Samba's TCP 445 and 139 (plus UDP 137/138) are blocked at the firewall. Services running and AppArmor showing no denials confirm the traffic never reaches smbd, making the firewall the cause.
- ✗
The Samba configuration file was corrupted during the update.
Why it's wrong here
The stem states the Samba configuration has not been changed recently, and smbd and nmbd are running, which a corrupted smb.conf would typically prevent. Configuration repair is the correct action when a syntax error or bad directive stops Samba from starting, not when services are healthy.
- ✗
The kernel update changed the default file system mount options, restricting access.
Why it's wrong here
Kernel patches do not rewrite mount options for existing filesystems, and a mount restriction would surface as permission or read-only errors rather than a complete loss of Samba share access. It is tempting because kernel updates can affect storage drivers, but here ufw allowing only port 22 explains the blocked SMB traffic.
- ✗
The AppArmor profile is preventing smbd from binding to network interfaces.
Why it's wrong here
AppArmor denials would appear in the audit or kernel logs, and the administrator found none, so the smbd profile is not blocking interface binding. AppArmor confinement is the right control when a service must be restricted to specific paths or capabilities, but here the evidence rules it out.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
AppArmor
AppArmor is a Linux kernel security module that restricts programs to a predefined set of resources using mandatory access control (MAC) policies.
Key term
Output
In IT service management, output is the result or deliverable produced by a process, system, or component, such as data, reports, or services delivered to a customer.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.