Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?

⚠ Common exam trap

Candidates often confuse file capabilities with POSIX ACLs or filesystem attributes, leading to tools like getfacl or lsattr instead of getcap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

getcap /usr/bin/ping

File capabilities allow a binary to perform privileged operations without being setuid root. The getcap command reads the security.capability extended attribute and reports capabilities such as cap_net_raw. Inspecting /usr/bin/ping with getcap confirms whether it can open raw sockets under least privilege, which is the goal of the administrator's verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    chacl -l /usr/bin/ping

    Why it's wrong here

    chacl is used to change or list access control lists on files, similar to getfacl. It manipulates POSIX ACL entries, not file capabilities. Using it on /usr/bin/ping would show ACLs, not the capability set, and therefore cannot verify that the binary holds cap_net_raw for raw socket operations.

  • ✗

    getfacl /usr/bin/ping

    Why it's wrong here

    getfacl displays POSIX access control lists, which govern discretionary permissions for users and groups on files. It does not report file capabilities such as cap_net_raw. Running it against /usr/bin/ping would show ACL entries, not the capability set, so it cannot confirm whether ping can open raw sockets without setuid root. The administrator needs a tool that reads the security.capability extended attribute.

  • ✗

    lsattr /usr/bin/ping

    Why it's wrong here

    lsattr lists filesystem attributes such as immutable, append-only, or no-dump flags on ext2/3/4 filesystems. It does not display Linux capabilities. While it could reveal that a file is immutable, it provides no information about cap_net_raw or any other capability, so it cannot answer whether ping can open raw sockets without setuid root.

  • ✓

    getcap /usr/bin/ping

    Why this is correct

    getcap reads and displays the file capabilities stored in the security.capability extended attribute of a binary. For /usr/bin/ping, it would report cap_net_raw=ep, confirming the binary can open raw sockets without setuid root. This is exactly the inspection the administrator needs to verify least-privilege configuration on the ping utility.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.