Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A Linux server hosts a web application that must be able to bind to TCP port 443. The administrator has already installed the application and configured it to listen on 443. However, when the service starts, it fails with a 'Permission denied' error. The administrator confirms that no other process is using port 443 and that the service runs as the non-root user 'webapp'. Which command should the administrator use to grant the necessary capability to the service binary without giving it full root privileges?

⚠ Common exam trap

The trap here is assuming that opening the firewall port or adding the user to a group will resolve a bind permission error, when the issue is about Linux capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

setcap 'cap_net_bind_service=+ep' /usr/local/bin/webapp

The service runs as a non-root user and needs to bind to a privileged port (443). Linux capabilities allow fine-grained privilege assignment. The setcap command with cap_net_bind_service grants exactly the needed capability, enabling the binary to bind to low-numbered ports without full root privileges. This follows the principle of least privilege and is the standard solution for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    chmod u+s /usr/local/bin/webapp

    Why it's wrong here

    Setting the setuid bit makes the binary run with the privileges of its owner (likely root), which would grant full root access, not just the ability to bind to port 443. This violates the principle of least privilege and introduces a significant security risk. It does not specifically address the capability needed for binding to privileged ports.

  • ✗

    firewall-cmd --add-port=443/tcp --permanent

    Why it's wrong here

    This command opens TCP port 443 in firewalld, which is about network filtering, not about granting a process permission to bind to a privileged port. The error occurs at the bind() system call, before any network traffic is involved. Opening the firewall port does not change the kernel's port binding restrictions for non-root users.

  • ✓

    setcap 'cap_net_bind_service=+ep' /usr/local/bin/webapp

    Why this is correct

    This command assigns the cap_net_bind_service capability to the webapp binary, allowing it to bind to privileged ports (below 1024) without running as root. The +ep flags set the effective and permitted capability sets, enabling the process to use the capability. This is the least-privilege approach and directly resolves the permission denied error for a non-root user.

  • ✗

    usermod -aG root webapp

    Why it's wrong here

    Adding the webapp user to the root group does not grant the ability to bind to privileged ports. Group membership in root typically provides access to files owned by the root group, but binding to ports below 1024 is controlled by capabilities, not group permissions. This would not resolve the permission denied error and could grant unintended file access.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.