XK0-006 System Management Practice Question
A developer wants to grant a user named 'john' read and write permissions to a file, but the file currently has an ACL that gives 'jane' full control. The administrator wants to add an ACL entry for 'john' without modifying existing entries. Which command accomplishes this?
⚠ Common exam trap
XK0-006 often tests the distinction between modifying and removing ACL entries, so candidates may confuse `-m` (modify/add) with `-x` (remove) or `-b` (remove all).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
setfacl -m u:john:rw file
The `setfacl -m` command modifies the ACL by adding or updating an entry for the specified user, leaving all other existing ACL entries intact. This directly satisfies the requirement to grant 'john' read and write permissions without altering 'jane's full control entry. The `-m` flag is specifically designed for modifying ACLs in this additive manner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
setfacl -x u:john:rw file
Why it's wrong here
The -x flag removes the named user entry for john, the opposite of adding one; no entry for john exists yet, so the command either errors or achieves nothing. Adding requires -m. It is tempting because -x is the natural counterpart when an administrator wants to change john's access, but it deletes rather than grants.
- ✗
setfacl -b u:john:rw file
Why it's wrong here
The -b flag removes all extended ACL entries, wiping jane's existing full-control entry, which directly violates the requirement to leave existing entries untouched. Adding john's entry requires -m to modify the ACL. It is tempting because -b is used when resetting a file's ACL entirely before rebuilding it.
- ✗
chmod u+rw file; setfacl -m u:john:rw file
Why it's wrong here
chmod u+rw alters the file owner's permissions, not john's, and does not add an ACL entry for him; the requirement concerns john specifically, not the owning user. The setfacl -m portion is correct, but the chmod prefix is irrelevant and potentially harmful. It is tempting because chmod is the familiar tool for granting file permissions.
- ✓
setfacl -m u:john:rw file
Why this is correct
The -m flag modifies the ACL by adding or replacing only the specified entry, leaving jane's existing full-control entry untouched. Using u:john:rw grants john read and write, satisfying the stem's requirement to avoid altering existing entries.
Visual reference
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
ACL
An Access Control List is a set of rules that determines who or what can access specific network resources or data.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.