Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?

⚠ Common exam trap

XK0-006 often tests the confusion between authentication modules (like pam_unix) and password quality modules (like pam_pwquality), or mistakenly selecting a PAM file for a specific service (sshd, login) instead of the common password stack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/pam.d/common-password with pam_pwquality.so

The pam_pwquality.so module is specifically designed to enforce password complexity policies such as minimum length, uppercase, digit, and special character requirements. It is configured in the password stack of PAM, typically in /etc/pam.d/common-password on Debian-based systems or /etc/pam.d/system-auth on RHEL-based systems. The options for pam_pwquality (e.g., minlen=12, ucredit=-1, dcredit=-1) directly map to the policy requirements. Therefore, /etc/pam.d/common-password with pam_pwquality.so is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/pam.d/login with pam_securetty.so

    Why it's wrong here

    pam_securetty.so only restricts which terminals root may log in from; it inspects no password content. It is tempting because /etc/pam.d/login is a genuine login stack. Complexity rules require pam_pwquality.so, which enforces minimum length and character classes at password change time.

  • ✗

    /etc/pam.d/sshd with pam_unix.so

    Why it's wrong here

    pam_unix.so handles authentication and password storage but enforces no composition rules; complexity checks belong to pam_pwquality.so via pam_pwhistory or password stack entries. It is tempting because sshd is the common remote login path, yet the policy must apply system-wide, not only to SSH sessions.

  • ✗

    /etc/pam.d/sudo with pam_permit.so

    Why it's wrong here

    pam_permit.so unconditionally allows access and performs no password checking whatsoever, so it cannot enforce length or character requirements. It is used for deliberately unrestricted services. Password complexity is enforced by pam_pwquality.so in the system password stack, not in sudo's authentication configuration.

  • ✓

    /etc/pam.d/common-password with pam_pwquality.so

    Why this is correct

    The pam_pwquality.so module enforces complexity rules through its ucredit, dcredit and minlen parameters, directly satisfying the policy's uppercase, digit and 12-character requirements. Placed in /etc/pam.d/common-password, it intercepts password changes via the password stack, rejecting non-compliant entries at update time.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.