XK0-006 Security Practice Question
A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?
⚠ Common exam trap
The trap here is choosing md5sum because it also produces a checksum, when the vendor published a SHA-256 value that must be matched with the same algorithm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sha256sum package.rpm
The sha256sum utility computes the SHA-256 digest of a file, allowing a direct comparison with the vendor's published checksum to confirm the download was not altered. The other commands either use a different algorithm, require signature artifacts not provided, or verify RPM signatures rather than a standalone hash file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
sha256sum package.rpm
Why this is correct
sha256sum computes the SHA-256 hash of the specified file and prints it, which the administrator can compare against the vendor's published checksum. It is the standard coreutils tool for this purpose and directly fulfills the integrity verification task. A match confirms the file matches the expected content.
- ✗
rpm --checksig package.rpm
Why it's wrong here
rpm --checksig verifies the GPG signature embedded in or associated with an RPM package using the imported RPM keys. It does not compute or compare a standalone SHA-256 checksum file. Since the vendor supplied a checksum rather than a package signature, this command does not perform the requested comparison.
- ✗
md5sum package.rpm
Why it's wrong here
md5sum computes an MD5 hash, which is a different algorithm from the SHA-256 checksum the vendor published. Comparing an MD5 value to a SHA-256 value is meaningless because the digests differ in length and algorithm. MD5 is also considered cryptographically broken for integrity purposes, so it is the wrong tool here.
- ✗
gpg --verify package.rpm
Why it's wrong here
gpg --verify checks a detached or inline signature against the file, which requires the vendor's public key and a signature file. The scenario provides only a checksum file, not a signature, so this command would fail or be inapplicable. It is a valid integrity method in other contexts but not what the checksum comparison requires.
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
Value
Value is the perceived worth, benefit, or usefulness that a service, product, or activity delivers to stakeholders, especially customers and the business.
Key term
rpm
RPM Package Manager (originally Red Hat Package Manager) is a powerful command-line utility for installing, updating, removing, querying, and verifying software packages on Linux systems that use the .rpm package format.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.