Courseiva
easyMultiple Choice

XK0-006 Practice Question: A junior administrator is tasked with setting up…

A junior administrator is tasked with setting up a file server using NFS on a Linux server. The /etc/exports file currently contains: /srv/nfs *(rw,sync,no_subtree_check). The administrator wants to restrict access to only the 192.168.10.0/24 network and require clients to use a privileged port (less than 1024) for added security. Additionally, the administrator wants to prevent root users on the client from having root access to the NFS share. Which exports configuration meets these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse 'secure' with 'insecure' — the 'secure' option requires privileged ports, while 'insecure' allows any port, and many mistakenly think 'insecure' is needed for security or that 'no_root_squash' is the default safe behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,secure,root_squash)

It restricts access to the 192.168.10.0/24 network, uses the 'secure' option to require client connections from a privileged port (less than 1024), and applies 'root_squash' to map root users on the client to the anonymous 'nobody' user, preventing root-level access to the NFS share.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,no_all_squash)

    Why it's wrong here

    no_all_squash preserves the original UID and GID of all remote users, so client root retains root privileges on the export, violating the requirement. It is tempting because no_all_squash is correctly used when UIDs and GIDs are synchronised across trusted hosts and identity preservation is needed for shared storage.

  • ✗

    /srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,insecure,root_squash)

    Why it's wrong here

    The insecure flag explicitly permits clients to connect from unprivileged source ports, directly contradicting the requirement for privileged ports below 1024. It is tempting because insecure is commonly added to resolve mount failures from clients that cannot bind reserved ports, which is the correct fix when privileged-port enforcement is not a requirement.

  • ✓

    /srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,secure,root_squash)

    Why this is correct

    This entry restricts the export to the 192.168.10.0/24 subnet, and secure enforces the privileged source port requirement. root_squash maps remote root to an anonymous user, preventing client root from gaining root access to the share, meeting all three stated constraints.

  • ✗

    /srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,secure,no_root_squash)

    Why it's wrong here

    no_root_squash maps remote root to local root, granting client root users full root access to the share, which the scenario explicitly forbids. It is tempting because no_root_squash is legitimately used for diskless clients or backup servers where root must preserve ownership and permissions across the export.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.