XK0-006 Security Practice Question
A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)
⚠ Common exam trap
Candidates often confuse password aging with complexity and assuming that a single PAM file or a deprecated module like pam_tally2 is sufficient for comprehensive lockout.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the pam_faillock module in /etc/pam.d/system-auth and /etc/pam.d/password-auth to lock accounts after a specified number of failed attempts.
To implement account lockout, the pam_faillock module must be configured in the PAM system-auth and password-auth files, which enforces lockout across authentication services. To enforce password complexity, the /etc/security/pwquality.conf file must be edited to set parameters like minlen and character class requirements. Together, these actions meet both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the line 'auth required pam_tally2.so deny=5' to /etc/pam.d/sshd to lock accounts after five failed SSH login attempts.
Why it's wrong here
While pam_tally2 can lock accounts after failed attempts, it is deprecated in favor of pam_faillock on modern Linux systems. Additionally, configuring it only in /etc/pam.d/sshd would limit lockout to SSH logins, not all authentication methods. The requirement is to protect the system generally, so a more comprehensive approach using pam_faillock in system-auth and password-auth is preferred. Thus, this action is not the best choice.
- ✓
Configure the pam_faillock module in /etc/pam.d/system-auth and /etc/pam.d/password-auth to lock accounts after a specified number of failed attempts.
Why this is correct
The pam_faillock module is designed to lock user accounts after a defined number of consecutive failed authentication attempts. Configuring it in the PAM files for system-auth and password-auth ensures that lockout applies to both login and password change operations. This directly addresses the requirement to implement account lockout, and it is the standard method on modern Linux distributions.
- ✗
Set the PASS_MAX_DAYS parameter to 90 in /etc/login.defs to enforce password expiration.
Why it's wrong here
PASS_MAX_DAYS controls password aging, not complexity or lockout. While password expiration is a good security practice, it does not enforce complexity rules (such as requiring mixed case, digits, and special characters) nor does it lock accounts after failed attempts. Therefore, it does not meet the stated goals of account lockout and password complexity.
- ✓
Edit /etc/security/pwquality.conf to set minlen=12, ucredit=-1, lcredit=-1, dcredit=-1, and ocredit=-1.
Why this is correct
The /etc/security/pwquality.conf file configures the pam_pwquality module, which enforces password complexity. Setting minlen=12 and the credit values to -1 requires at least one uppercase, lowercase, digit, and special character, and a minimum length of 12. This directly fulfills the password complexity requirement, and the module is invoked during password changes.
- ✗
Set the UMASK value to 077 in /etc/login.defs to restrict default file permissions.
Why it's wrong here
The UMASK setting controls default permissions for newly created files and directories, enhancing security by restricting access. However, it has no effect on account lockout or password complexity. It addresses a different aspect of system hardening, so it does not help achieve the specific goals of lockout and complexity.
Go deeper
Related to this question
Learn chapter
File Transfer and Remote Access
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.