XK0-006 Security Practice Question
A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?
⚠ Common exam trap
The trap here is assuming that restrictive modes, chattr +i, or mount options can constrain root, when the kernel's discretionary access control always exempts UID 0 from read and write permission checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt the file with a tool such as gpg or openssl enc using a key that is never stored on the server.
Traditional Unix permissions, including restrictive modes and special attributes, are enforced by the kernel, and root is deliberately exempt from those checks. The only way to guarantee that even root cannot read a file's contents is to encrypt it and keep the decryption key off the server, shifting enforcement from the permission model to cryptography that root cannot bypass.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Encrypt the file with a tool such as gpg or openssl enc using a key that is never stored on the server.
Why this is correct
When the file is encrypted and the decryption key resides only off the server, possession of root on that host yields nothing but ciphertext. Access control is enforced by cryptography rather than by the kernel's permission model, so even the superuser cannot recover the ledger contents without the external key.
- ✗
Set the file mode to 0660 and change its group owner to payroll.
Why it's wrong here
Mode 0660 with group payroll blocks ordinary users outside the group, but the root account bypasses discretionary permission checks entirely. Root can still open and read the ledger file, so this configuration does not meet the policy requirement that even root be unable to read the contents.
- ✗
Place the file on a filesystem mounted with the noexec and nodev options.
Why it's wrong here
Mount options such as noexec and nodev restrict execution of binaries and interpretation of device nodes on that filesystem. They have no bearing on whether a file can be opened and read, so root retains full read access to the ledger and the requirement remains unmet.
- ✗
Apply the immutable attribute to the file with chattr +i /srv/payroll/ledger.db.
Why it's wrong here
The immutable attribute prevents modification, deletion, and renaming even by root, but it does not restrict reading. Root can still open the ledger and view its contents, and the attribute also blocks the legitimate writes the payroll application needs, so it fails the stated policy.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.