XK0-006 Security Practice Question
A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?
⚠ Common exam trap
Candidates often confuse file capabilities with POSIX ACLs or filesystem attributes, leading to tools like getfacl or lsattr instead of getcap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
getcap /usr/bin/ping
File capabilities allow a binary to perform privileged operations without being setuid root. The getcap command reads the security.capability extended attribute and reports capabilities such as cap_net_raw. Inspecting /usr/bin/ping with getcap confirms whether it can open raw sockets under least privilege, which is the goal of the administrator's verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
chacl -l /usr/bin/ping
Why it's wrong here
chacl is used to change or list access control lists on files, similar to getfacl. It manipulates POSIX ACL entries, not file capabilities. Using it on /usr/bin/ping would show ACLs, not the capability set, and therefore cannot verify that the binary holds cap_net_raw for raw socket operations.
- ✗
getfacl /usr/bin/ping
Why it's wrong here
getfacl displays POSIX access control lists, which govern discretionary permissions for users and groups on files. It does not report file capabilities such as cap_net_raw. Running it against /usr/bin/ping would show ACL entries, not the capability set, so it cannot confirm whether ping can open raw sockets without setuid root. The administrator needs a tool that reads the security.capability extended attribute.
- ✗
lsattr /usr/bin/ping
Why it's wrong here
lsattr lists filesystem attributes such as immutable, append-only, or no-dump flags on ext2/3/4 filesystems. It does not display Linux capabilities. While it could reveal that a file is immutable, it provides no information about cap_net_raw or any other capability, so it cannot answer whether ping can open raw sockets without setuid root.
- ✓
getcap /usr/bin/ping
Why this is correct
getcap reads and displays the file capabilities stored in the security.capability extended attribute of a binary. For /usr/bin/ping, it would report cap_net_raw=ep, confirming the binary can open raw sockets without setuid root. This is exactly the inspection the administrator needs to verify least-privilege configuration on the ping utility.
Go deeper
Related to this question
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.