Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A security audit reveals that the system's PAM configuration does not enforce password complexity. Which PAM module and configuration line should be added to /etc/pam.d/common-password to require at least one uppercase letter, one digit, and a minimum length of 12 characters?

⚠ Common exam trap

XK0-006 often tests the difference between pam_pwquality and pam_cracklib, and candidates may incorrectly choose pam_cracklib due to its historical use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1

The pam_pwquality.so module is the modern replacement for pam_cracklib.so and provides password quality enforcement. The line 'password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1' correctly sets the minimum length to 12 and requires at least one uppercase letter (ucredit=-1) and one digit (dcredit=-1). The 'requisite' control ensures that if this module fails, the password change is rejected immediately.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1

    Why this is correct

    `pam_pwquality.so` enforces complexity at password-change time, and the negative credit values are the mechanism: `ucredit=-1` and `dcredit=-1` each demand at least one uppercase letter and one digit, while `minlen=12` sets the minimum length. The `requisite` control ensures failure blocks the password change immediately, satisfying the audit's complexity requirement.

  • ✗

    password sufficient pam_faillock.so minlen=12 ucredit=-1 dcredit=-1

    Why it's wrong here

    pam_faillock.so locks accounts after repeated failed logins; it does not parse minlen, ucredit or dcredit, so password complexity is never checked. It is tempting because faillock is a genuine PAM security module, and would be the correct choice when the audit finding concerned brute-force lockout thresholds rather than composition rules.

  • ✗

    password required pam_cracklib.so minlen=12 ucredit=-1 dcredit=-1

    Why it's wrong here

    pam_cracklib.so is deprecated and removed from current distributions; on the target system the module cannot be loaded, so the line fails and complexity is not enforced. It is tempting because cracklib historically performed exactly this check, and would be correct on older systems before pam_pwquality.so replaced it.

  • ✗

    password required pam_unix.so minlen=12 ucredit=-1 dcredit=-1

    Why it's wrong here

    pam_unix.so's ucredit and dcredit parameters are not recognised by that module, so the line fails to enforce complexity; pam_cracklib (or pam_pwquality) is the module providing credit-based checks. It is tempting because pam_unix.so does handle minlen, but complexity rules belong to the password-quality module, not the authentication module.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.