XK0-006 Security Practice Question
A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?
⚠ Common exam trap
XK0-006 often tests the specific PAM module for password complexity; candidates may confuse pam_pwquality with pam_unix or lockout modules like pam_tally2 or pam_faillock, but the key is that only pam_pwquality provides the granular complexity controls required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pam_pwquality.so
The pam_pwquality.so module is specifically designed to enforce password complexity policies, such as minimum length, required character classes (uppercase, lowercase, digits, special characters), and dictionary checks. Configuring it in /etc/pam.d/common-password allows the administrator to set parameters like minlen=12, ucredit=-1, and dcredit=-1 to meet the stated requirements. This module is the standard replacement for the older pam_cracklib.so.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pam_unix.so
Why it's wrong here
pam_unix.so handles password hashing and storage, delegating complexity checks to modules such as pam_pwquality or pam_cracklib. It is tempting because it is already present in common-password, but it would be the right choice when the requirement is to change the hashing algorithm rather than enforce composition rules.
- ✓
pam_pwquality.so
Why this is correct
Configuring pam_pwquality.so in /etc/pam.d/common-password enforces the auditor's complexity requirement directly, using parameters such as minlen=12, ucredit=-1 and dcredit=-1 to mandate twelve characters, one uppercase letter and one digit. Unlike pam_cracklib.so, it reads settings from /etc/security/pwquality.conf, centralising policy across services.
- ✗
pam_tally2.so
Why it's wrong here
pam_tally2.so counts failed login attempts and locks accounts, offering no length, uppercase or digit checks. It is tempting because it appears in security hardening guidance alongside password rules, and it would be correct where the goal is to deny access after repeated failures rather than to constrain password composition.
- ✗
pam_faillock.so
Why it's wrong here
pam_faillock.so locks accounts after repeated authentication failures; it does not inspect or enforce password composition. It is tempting because it is a security-hardening PAM module placed in common-auth, and it would be the right choice when the requirement is to throttle brute-force attempts rather than enforce complexity.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.