Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

A Linux administrator is configuring a system to use a centralized authentication service. The requirement is that if the central server is unreachable, users should still be able to log in using cached credentials. Which PAM module should be configured to provide this functionality?

⚠ Common exam trap

The trap here is thinking that pam_sss alone provides caching; it requires SSSD to be configured with cache_credentials enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

pam_sss with caching enabled in SSSD

SSSD with caching enabled provides offline authentication by storing credentials locally. The pam_sss module integrates with SSSD, and when the central server is down, SSSD uses its cache to validate credentials. Other modules like pam_unix only handle local accounts, and pam_ccreds is deprecated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pam_ccreds

    Why it's wrong here

    pam_ccreds is designed to cache credentials for offline authentication, but it is deprecated and not commonly used in modern distributions. It stores credentials locally and validates them when the central server is unavailable. However, it is not the standard module for this purpose in current Linux systems, and its use is discouraged.

  • ✓

    pam_sss with caching enabled in SSSD

    Why this is correct

    The pam_sss module works with SSSD to authenticate users. When SSSD is configured with caching (e.g., cache_credentials = True), it stores user credentials locally, allowing offline authentication when the central server is unreachable. This is the standard method for providing cached credentials in modern Linux environments.

  • ✗

    pam_unix

    Why it's wrong here

    pam_unix authenticates against local files like /etc/passwd and /etc/shadow. It does not interact with centralized authentication services or cache remote credentials. It would only work for local accounts and does not provide failover for network-based authentication.

  • ✗

    pam_sss

    Why it's wrong here

    pam_sss is the PAM module for System Security Services Daemon (SSSD), which can provide caching for offline authentication. However, SSSD itself must be configured with caching enabled, and the module alone does not automatically cache credentials. The question asks for the PAM module that provides cached credentials, and pam_sss relies on SSSD's cache, not its own. It is not the module that directly implements caching.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.