XK0-006 Security Practice Question
A Linux administrator is configuring a server to use a centralized authentication service. The security policy requires that user credentials are never sent in clear text and that the authentication traffic is encrypted. The administrator decides to use LDAP with TLS. Which command should be used to verify that the LDAP server's certificate is valid and that the TLS handshake succeeds?
⚠ Common exam trap
The trap here is using ldapsearch with an ldap:// URI and assuming it tests encryption, when it actually connects in clear text unless StartTLS is explicitly requested.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
openssl s_client -connect ldap.example.com:636 -showcerts
The openssl s_client command is designed to test TLS connections, making it ideal for verifying the LDAP server's certificate and handshake on the LDAPS port. It displays the certificate chain and any errors, ensuring that the encryption is correctly configured. Other commands either connect without encryption, check only for listening sockets, or do not validate the certificate in the LDAP context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ss -tlnp | grep 636
Why it's wrong here
The ss command lists listening sockets and shows whether a service is bound to port 636. It confirms that the LDAP server is listening on the LDAPS port but does not perform any TLS handshake or certificate validation. It cannot verify the certificate's validity or the encryption strength.
- ✗
nmap --script ssl-enum-ciphers -p 389 ldap.example.com
Why it's wrong here
nmap's ssl-enum-ciphers script enumerates supported ciphers on a TLS-enabled port. However, port 389 typically runs plain LDAP, not TLS, unless StartTLS is used. Running the script against port 389 may not yield a TLS handshake, and it does not validate the certificate chain or verify the LDAP server's identity in the context of LDAP authentication.
- ✗
ldapsearch -H ldap://ldap.example.com -x -b '' -s base
Why it's wrong here
ldapsearch with an ldap:// URI connects to the standard LDAP port (389) without encryption. It queries the root DSE but does not test TLS. To test TLS, the URI should use ldaps:// or the -ZZ option for StartTLS. This command would send traffic in clear text, failing the security requirement.
- ✓
openssl s_client -connect ldap.example.com:636 -showcerts
Why this is correct
openssl s_client initiates a TLS connection to the specified host and port, displaying the server's certificate chain and the result of the handshake. Using port 636, the standard LDAPS port, this command verifies that the LDAP server presents a valid certificate and that TLS negotiation succeeds, directly addressing the requirement.
Go deeper
Related to this question
Learn chapter
Installing Linux and Package Management
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.