hardMultiple Choice
XK0-006 Practice Question: A Linux system experiences high CPU usage from a…
A Linux system experiences high CPU usage from a process that appears to be a fork bomb. The administrator wants to prevent such attacks in the future by limiting the number of processes a user can create. Which configuration file should be modified, and what parameter should be set?
⚠ Common exam trap
CompTIA often tests the distinction between system-wide PID limits (kernel.pid_max) and per-user process limits (nproc), and candidates mistakenly choose A because they confuse maximum PID number with maximum number of processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'username hard nproc 100' in /etc/security/limits.conf
/etc/security/limits.conf is the PAM-based configuration file used to set per-user resource limits via the 'nproc' parameter. Adding 'username hard nproc 100' enforces a hard limit of 100 processes for that user, preventing a fork bomb from exhausting system resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set 'kernel.pid_max=100' in /etc/sysctl.conf
Why it's wrong here
kernel.pid_max caps the total process ID number, not the number of processes a user may create, so a fork bomb still exhausts CPU. It is tempting because it is a kernel process limit. The correct control is nproc in /etc/security/limits.conf, which restricts per-user process counts.
- ✗
Set 'DefaultLimitNPROC=100' in /etc/systemd/system.conf
Why it's wrong here
DefaultLimitNPROC in /etc/systemd/system.conf sets a default for systemd-managed units only, so processes started outside systemd, such as interactive shells, are not capped. It is tempting because it is a genuine per-user process limit. The correct file is /etc/security/limits.conf, applied by pam_limits.
- ✓
Add 'username hard nproc 100' in /etc/security/limits.conf
Why this is correct
The nproc limit in /etc/security/limits.conf caps processes per user via PAM, so a hard limit of 100 stops any single account exhausting the process table. This directly addresses the fork bomb constraint by preventing runaway process creation.
- ✗
Add 'ulimit -u 100' to /etc/profile
Why it's wrong here
Adding ulimit -u to /etc/profile applies only to interactive login shells, so services, cron jobs and non-login sessions bypass it, leaving the fork bomb unchecked. It is tempting because ulimit -u does set a per-user process limit. Persistent enforcement belongs in /etc/security/limits.conf via pam_limits.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Process
In IT service management, a process is a structured set of activities designed to accomplish a specific objective, such as managing incidents or changes, by transforming inputs into defined outputs.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.