XK0-006 Security Practice Question
A Linux server hosts a web application that must be able to bind to TCP port 443. The administrator has already installed the application and configured it to listen on 443. However, when the service starts, it fails with a 'Permission denied' error. The administrator confirms that no other process is using port 443 and that the service runs as the non-root user 'webapp'. Which command should the administrator use to grant the necessary capability to the service binary without giving it full root privileges?
⚠ Common exam trap
The trap here is assuming that opening the firewall port or adding the user to a group will resolve a bind permission error, when the issue is about Linux capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
setcap 'cap_net_bind_service=+ep' /usr/local/bin/webapp
The service runs as a non-root user and needs to bind to a privileged port (443). Linux capabilities allow fine-grained privilege assignment. The setcap command with cap_net_bind_service grants exactly the needed capability, enabling the binary to bind to low-numbered ports without full root privileges. This follows the principle of least privilege and is the standard solution for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
chmod u+s /usr/local/bin/webapp
Why it's wrong here
Setting the setuid bit makes the binary run with the privileges of its owner (likely root), which would grant full root access, not just the ability to bind to port 443. This violates the principle of least privilege and introduces a significant security risk. It does not specifically address the capability needed for binding to privileged ports.
- ✗
firewall-cmd --add-port=443/tcp --permanent
Why it's wrong here
This command opens TCP port 443 in firewalld, which is about network filtering, not about granting a process permission to bind to a privileged port. The error occurs at the bind() system call, before any network traffic is involved. Opening the firewall port does not change the kernel's port binding restrictions for non-root users.
- ✓
setcap 'cap_net_bind_service=+ep' /usr/local/bin/webapp
Why this is correct
This command assigns the cap_net_bind_service capability to the webapp binary, allowing it to bind to privileged ports (below 1024) without running as root. The +ep flags set the effective and permitted capability sets, enabling the process to use the capability. This is the least-privilege approach and directly resolves the permission denied error for a non-root user.
- ✗
usermod -aG root webapp
Why it's wrong here
Adding the webapp user to the root group does not grant the ability to bind to privileged ports. Group membership in root typically provides access to files owned by the root group, but binding to ports below 1024 is controlled by capabilities, not group permissions. This would not resolve the permission denied error and could grant unintended file access.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
Process
In IT service management, a process is a structured set of activities designed to accomplish a specific objective, such as managing incidents or changes, by transforming inputs into defined outputs.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.