Courseiva
Security →mediumMultiple Select

XK0-006 Security Practice Question

A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)

⚠ Common exam trap

Candidates often confuse password aging with complexity and assuming that a single PAM file or a deprecated module like pam_tally2 is sufficient for comprehensive lockout.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the pam_faillock module in /etc/pam.d/system-auth and /etc/pam.d/password-auth to lock accounts after a specified number of failed attempts.

To implement account lockout, the pam_faillock module must be configured in the PAM system-auth and password-auth files, which enforces lockout across authentication services. To enforce password complexity, the /etc/security/pwquality.conf file must be edited to set parameters like minlen and character class requirements. Together, these actions meet both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the line 'auth required pam_tally2.so deny=5' to /etc/pam.d/sshd to lock accounts after five failed SSH login attempts.

    Why it's wrong here

    While pam_tally2 can lock accounts after failed attempts, it is deprecated in favor of pam_faillock on modern Linux systems. Additionally, configuring it only in /etc/pam.d/sshd would limit lockout to SSH logins, not all authentication methods. The requirement is to protect the system generally, so a more comprehensive approach using pam_faillock in system-auth and password-auth is preferred. Thus, this action is not the best choice.

  • ✓

    Configure the pam_faillock module in /etc/pam.d/system-auth and /etc/pam.d/password-auth to lock accounts after a specified number of failed attempts.

    Why this is correct

    The pam_faillock module is designed to lock user accounts after a defined number of consecutive failed authentication attempts. Configuring it in the PAM files for system-auth and password-auth ensures that lockout applies to both login and password change operations. This directly addresses the requirement to implement account lockout, and it is the standard method on modern Linux distributions.

  • ✗

    Set the PASS_MAX_DAYS parameter to 90 in /etc/login.defs to enforce password expiration.

    Why it's wrong here

    PASS_MAX_DAYS controls password aging, not complexity or lockout. While password expiration is a good security practice, it does not enforce complexity rules (such as requiring mixed case, digits, and special characters) nor does it lock accounts after failed attempts. Therefore, it does not meet the stated goals of account lockout and password complexity.

  • ✓

    Edit /etc/security/pwquality.conf to set minlen=12, ucredit=-1, lcredit=-1, dcredit=-1, and ocredit=-1.

    Why this is correct

    The /etc/security/pwquality.conf file configures the pam_pwquality module, which enforces password complexity. Setting minlen=12 and the credit values to -1 requires at least one uppercase, lowercase, digit, and special character, and a minimum length of 12. This directly fulfills the password complexity requirement, and the module is invoked during password changes.

  • ✗

    Set the UMASK value to 077 in /etc/login.defs to restrict default file permissions.

    Why it's wrong here

    The UMASK setting controls default permissions for newly created files and directories, enhancing security by restricting access. However, it has no effect on account lockout or password complexity. It addresses a different aspect of system hardening, so it does not help achieve the specific goals of lockout and complexity.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.