Courseiva
Security →easyMultiple Choice

XK0-006 Security Practice Question

A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?

⚠ Common exam trap

The trap here is choosing md5sum because it also produces a checksum, when the vendor published a SHA-256 value that must be matched with the same algorithm.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sha256sum package.rpm

The sha256sum utility computes the SHA-256 digest of a file, allowing a direct comparison with the vendor's published checksum to confirm the download was not altered. The other commands either use a different algorithm, require signature artifacts not provided, or verify RPM signatures rather than a standalone hash file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    sha256sum package.rpm

    Why this is correct

    sha256sum computes the SHA-256 hash of the specified file and prints it, which the administrator can compare against the vendor's published checksum. It is the standard coreutils tool for this purpose and directly fulfills the integrity verification task. A match confirms the file matches the expected content.

  • ✗

    rpm --checksig package.rpm

    Why it's wrong here

    rpm --checksig verifies the GPG signature embedded in or associated with an RPM package using the imported RPM keys. It does not compute or compare a standalone SHA-256 checksum file. Since the vendor supplied a checksum rather than a package signature, this command does not perform the requested comparison.

  • ✗

    md5sum package.rpm

    Why it's wrong here

    md5sum computes an MD5 hash, which is a different algorithm from the SHA-256 checksum the vendor published. Comparing an MD5 value to a SHA-256 value is meaningless because the digests differ in length and algorithm. MD5 is also considered cryptographically broken for integrity purposes, so it is the wrong tool here.

  • ✗

    gpg --verify package.rpm

    Why it's wrong here

    gpg --verify checks a detached or inline signature against the file, which requires the vendor's public key and a signature file. The scenario provides only a checksum file, not a signature, so this command would fail or be inapplicable. It is a valid integrity method in other contexts but not what the checksum comparison requires.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.