Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?

⚠ Common exam trap

The trap here is assuming that restrictive modes, chattr +i, or mount options can constrain root, when the kernel's discretionary access control always exempts UID 0 from read and write permission checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt the file with a tool such as gpg or openssl enc using a key that is never stored on the server.

Traditional Unix permissions, including restrictive modes and special attributes, are enforced by the kernel, and root is deliberately exempt from those checks. The only way to guarantee that even root cannot read a file's contents is to encrypt it and keep the decryption key off the server, shifting enforcement from the permission model to cryptography that root cannot bypass.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Encrypt the file with a tool such as gpg or openssl enc using a key that is never stored on the server.

    Why this is correct

    When the file is encrypted and the decryption key resides only off the server, possession of root on that host yields nothing but ciphertext. Access control is enforced by cryptography rather than by the kernel's permission model, so even the superuser cannot recover the ledger contents without the external key.

  • ✗

    Set the file mode to 0660 and change its group owner to payroll.

    Why it's wrong here

    Mode 0660 with group payroll blocks ordinary users outside the group, but the root account bypasses discretionary permission checks entirely. Root can still open and read the ledger file, so this configuration does not meet the policy requirement that even root be unable to read the contents.

  • ✗

    Place the file on a filesystem mounted with the noexec and nodev options.

    Why it's wrong here

    Mount options such as noexec and nodev restrict execution of binaries and interpretation of device nodes on that filesystem. They have no bearing on whether a file can be opened and read, so root retains full read access to the ledger and the requirement remains unmet.

  • ✗

    Apply the immutable attribute to the file with chattr +i /srv/payroll/ledger.db.

    Why it's wrong here

    The immutable attribute prevents modification, deletion, and renaming even by root, but it does not restrict reading. Root can still open the ledger and view its contents, and the attribute also blocks the legitimate writes the payroll application needs, so it fails the stated policy.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.