Courseiva
easyMultiple Choice

XK0-006 Practice Question: A Linux server is configured to use Pluggable…

A Linux server is configured to use Pluggable Authentication Modules (PAM). Which file is used to define the authentication order for the 'sshd' service?

⚠ Common exam trap

CompTIA often tests the distinction between /etc/pam.d/sshd and /etc/pam.d/login, as candidates may confuse the SSH service file with the general login file, especially since both handle authentication but for different services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/pam.d/sshd

In Linux, PAM configuration files for individual services are stored in /etc/pam.d/, with the filename matching the service name. For the sshd service, the file /etc/pam.d/sshd defines the authentication order, including the modules and their control flags (e.g., required, sufficient) that PAM will consult during SSH login. This is the standard location per the Linux PAM architecture, as documented in the pam.conf man page.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/authselect/sshd

    Why it's wrong here

    /etc/authselect/sshd is not where PAM authentication order is defined; authselect manages system-wide profile selection and generates PAM files, while the effective stack for sshd lives in /etc/pam.d/sshd. It is tempting because authselect does influence PAM configuration, and it would be correct when switching system auth profiles.

  • ✗

    /etc/security/sshd

    Why it's wrong here

    PAM reads per-service configuration from /etc/pam.d/, and no /etc/security/sshd file defines authentication order; that directory holds module-specific configuration such as limits or access.conf. It is tempting because PAM modules do read files under /etc/security, and it would be correct for module parameters rather than the stack itself.

  • ✓

    /etc/pam.d/sshd

    Why this is correct

    PAM reads per-service configuration from /etc/pam.d/, so the sshd file defines the module stack and order applied to SSH logins. Editing /etc/pam.conf or another service's file would not affect sshd, making this the file that satisfies the service-specific ordering requirement.

  • ✗

    /etc/pam.d/login

    Why it's wrong here

    /etc/pam.d/login defines the authentication stack for local console logins, not the sshd service, so it does not govern SSH authentication order. It is tempting because it is a genuine PAM service file with the same syntax, and it would be correct when configuring local terminal login behaviour.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.