Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?

⚠ Common exam trap

XK0-006 often tests the specific PAM module for password complexity; candidates may confuse pam_pwquality with pam_unix or lockout modules like pam_tally2 or pam_faillock, but the key is that only pam_pwquality provides the granular complexity controls required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

pam_pwquality.so

The pam_pwquality.so module is specifically designed to enforce password complexity policies, such as minimum length, required character classes (uppercase, lowercase, digits, special characters), and dictionary checks. Configuring it in /etc/pam.d/common-password allows the administrator to set parameters like minlen=12, ucredit=-1, and dcredit=-1 to meet the stated requirements. This module is the standard replacement for the older pam_cracklib.so.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pam_unix.so

    Why it's wrong here

    pam_unix.so handles password hashing and storage, delegating complexity checks to modules such as pam_pwquality or pam_cracklib. It is tempting because it is already present in common-password, but it would be the right choice when the requirement is to change the hashing algorithm rather than enforce composition rules.

  • ✓

    pam_pwquality.so

    Why this is correct

    Configuring pam_pwquality.so in /etc/pam.d/common-password enforces the auditor's complexity requirement directly, using parameters such as minlen=12, ucredit=-1 and dcredit=-1 to mandate twelve characters, one uppercase letter and one digit. Unlike pam_cracklib.so, it reads settings from /etc/security/pwquality.conf, centralising policy across services.

  • ✗

    pam_tally2.so

    Why it's wrong here

    pam_tally2.so counts failed login attempts and locks accounts, offering no length, uppercase or digit checks. It is tempting because it appears in security hardening guidance alongside password rules, and it would be correct where the goal is to deny access after repeated failures rather than to constrain password composition.

  • ✗

    pam_faillock.so

    Why it's wrong here

    pam_faillock.so locks accounts after repeated authentication failures; it does not inspect or enforce password composition. It is tempting because it is a security-hardening PAM module placed in common-auth, and it would be the right choice when the requirement is to throttle brute-force attempts rather than enforce complexity.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.