Courseiva
System Management →mediumMultiple Select

XK0-006 System Management Practice Question

A Linux administrator needs to add an ACL entry to grant read permission to a user named 'jdoe' on a file. Which TWO commands can be used to achieve this? (Select TWO).

⚠ Common exam trap

The trap is confusing ACL modification with ownership change (chown) or standard permission change (chmod), and failing to recognize that -m and --modify are equivalent long/short options for setfacl.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

setfacl -m u:jdoe:r file

Option A, `setfacl -m u:jdoe:r file`, is correct because `-m` is the short form of `--modify`, and `u:jdoe:r` adds or modifies an ACL entry granting user jdoe read permission on the file. Option B, `setfacl --modify u:jdoe:r file`, is correct because it is the long-form equivalent of the same command, performing the identical ACL modification. Option C, `chown jdoe file`, only changes the file's owner and does not create an ACL entry, so it does not grant read permission via ACL. Option D, `setfacl -x u:jdoe file`, removes an existing ACL entry for jdoe rather than adding one. Option E, `chmod u+r file`, modifies the standard Unix permission bits for the file's owner, not an ACL entry for jdoe.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    setfacl -m u:jdoe:r file

    Why this is correct

    setfacl -m invokes modify mode, and the entry u:jdoe:r adds an ACL granting user jdoe read permission on the file without altering the existing owner, group or other bits. This directly satisfies the requirement to add a read ACL entry for that named user.

  • ✓

    setfacl --modify u:jdoe:r file

    Why this is correct

    setfacl --modify is the long-form equivalent of -m, and u:jdoe:r specifies a user entry granting jdoe read access. It adds the ACL entry to the file's access ACL, satisfying the requirement identically to the short-option form.

  • ✗

    chown jdoe file

    Why it's wrong here

    chown changes file ownership, not the ACL entry list, so it cannot grant jdoe read permission while leaving the existing owner intact. It is tempting because ownership and permissions are closely related, and chown is correct when the requirement is transferring a file to a different user or group.

  • ✗

    setfacl -x u:jdoe file

    Why it's wrong here

    The -x flag removes an existing ACL entry rather than adding one, so no read permission is granted to jdoe. It is tempting because setfacl is the correct tool family, and -m u:jdoe:r would add the entry this scenario requires.

  • ✗

    chmod u+r file

    Why it's wrong here

    chmod u+r alters only the file's owning-user permission bits, so it cannot create a named-user ACL entry for jdoe. It is tempting because chmod does manipulate permissions, and setfacl -m u:jdoe:r is the actual command that adds the ACL entry.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.