Courseiva
Security →mediumMultiple Select

XK0-006 Security Practice Question

A Linux engineer needs to restrict resource usage for users in the 'developers' group. Which TWO files or commands can be used to set ulimit values?

⚠ Common exam trap

Many exam-takers confuse the configuration file (/etc/security/limits.conf) with the PAM module file (/etc/pam.d/login) or think the ulimit command alone can set persistent limits for a group, when in fact ulimit only affects the current shell session and is not persistent across logins for all group members.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/security/limits.conf

Option B, /etc/security/limits.conf, is correct because this is the PAM configuration file where persistent per-user or per-group resource limits (such as nproc, nofile, or memlock) are defined using entries like '@developers hard nproc 20'. Option E, the ulimit command, is correct because it is the shell builtin used to view or set soft and hard resource limits for the current shell session, for example 'ulimit -u 20' to cap processes. Option C is not correct on its own because /etc/pam.d/login with pam_limits.so is the PAM module that enforces the limits defined in limits.conf, but it is not where the ulimit values themselves are set. Option A, sysctl, is incorrect because it tunes kernel parameters at runtime (e.g., net.ipv4.ip_forward) rather than per-user resource limits. Option D, /etc/ulimit.conf, is incorrect because no such standard file exists for setting ulimit values.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    sysctl command

    Why it's wrong here

    sysctl tunes kernel parameters at runtime, not per-user resource limits; ulimit values come from /etc/security/limits.conf and the ulimit command. It is tempting because sysctl also adjusts system-wide kernel behaviour, and would be correct for changing networking or memory parameters such as IP forwarding.

  • ✓

    /etc/security/limits.conf

    Why this is correct

    /etc/security/limits.conf defines per-user and per-group ulimit values, letting the engineer apply soft and hard resource caps to the 'developers' group through a group entry, which satisfies the requirement to restrict resource usage for that group.

  • ✗

    /etc/pam.d/login with pam_limits.so

    Why it's wrong here

    pam_limits.so enforces limits at login via PAM, but the question asks which files or commands set ulimit values themselves; PAM applies them rather than defining them. It is tempting because pam_limits.so is the standard mechanism for per-group limits, and would be correct when the requirement is enforcing limits for the developers group at session start.

  • ✗

    /etc/ulimit.conf

    Why it's wrong here

    No /etc/ulimit.conf file exists on Linux; ulimit values are set via /etc/security/limits.conf, limits.d drop-ins, or the shell builtin. It is tempting because the name mirrors other /etc configuration files, and such a file would be correct only if the distribution actually shipped one.

  • ✓

    ulimit command

    Why this is correct

    The ulimit command sets per-shell resource limits such as file descriptors, processes and memory for the current session or, with flags, for a user. It satisfies the requirement to restrict resource usage for the developers group.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.