easyMultiple Choice
XK0-006 Practice Question: A Linux server is configured to use Pluggable…
A Linux server is configured to use Pluggable Authentication Modules (PAM). Which file is used to define the authentication order for the 'sshd' service?
⚠ Common exam trap
CompTIA often tests the distinction between /etc/pam.d/sshd and /etc/pam.d/login, as candidates may confuse the SSH service file with the general login file, especially since both handle authentication but for different services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/pam.d/sshd
In Linux, PAM configuration files for individual services are stored in /etc/pam.d/, with the filename matching the service name. For the sshd service, the file /etc/pam.d/sshd defines the authentication order, including the modules and their control flags (e.g., required, sufficient) that PAM will consult during SSH login. This is the standard location per the Linux PAM architecture, as documented in the pam.conf man page.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/authselect/sshd
Why it's wrong here
/etc/authselect/sshd is not where PAM authentication order is defined; authselect manages system-wide profile selection and generates PAM files, while the effective stack for sshd lives in /etc/pam.d/sshd. It is tempting because authselect does influence PAM configuration, and it would be correct when switching system auth profiles.
- ✗
/etc/security/sshd
Why it's wrong here
PAM reads per-service configuration from /etc/pam.d/, and no /etc/security/sshd file defines authentication order; that directory holds module-specific configuration such as limits or access.conf. It is tempting because PAM modules do read files under /etc/security, and it would be correct for module parameters rather than the stack itself.
- ✓
/etc/pam.d/sshd
Why this is correct
PAM reads per-service configuration from /etc/pam.d/, so the sshd file defines the module stack and order applied to SSH logins. Editing /etc/pam.conf or another service's file would not affect sshd, making this the file that satisfies the service-specific ordering requirement.
- ✗
/etc/pam.d/login
Why it's wrong here
/etc/pam.d/login defines the authentication stack for local console logins, not the sshd service, so it does not govern SSH authentication order. It is tempting because it is a genuine PAM service file with the same syntax, and it would be correct when configuring local terminal login behaviour.
Go deeper
Related to this question
Learn chapter
Networking Fundamentals and Configuration
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.