XK0-006 Security Practice Question
A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?
⚠ Common exam trap
XK0-006 often tests the confusion between authentication modules (like pam_unix) and password quality modules (like pam_pwquality), or mistakenly selecting a PAM file for a specific service (sshd, login) instead of the common password stack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/pam.d/common-password with pam_pwquality.so
The pam_pwquality.so module is specifically designed to enforce password complexity policies such as minimum length, uppercase, digit, and special character requirements. It is configured in the password stack of PAM, typically in /etc/pam.d/common-password on Debian-based systems or /etc/pam.d/system-auth on RHEL-based systems. The options for pam_pwquality (e.g., minlen=12, ucredit=-1, dcredit=-1) directly map to the policy requirements. Therefore, /etc/pam.d/common-password with pam_pwquality.so is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/pam.d/login with pam_securetty.so
Why it's wrong here
pam_securetty.so only restricts which terminals root may log in from; it inspects no password content. It is tempting because /etc/pam.d/login is a genuine login stack. Complexity rules require pam_pwquality.so, which enforces minimum length and character classes at password change time.
- ✗
/etc/pam.d/sshd with pam_unix.so
Why it's wrong here
pam_unix.so handles authentication and password storage but enforces no composition rules; complexity checks belong to pam_pwquality.so via pam_pwhistory or password stack entries. It is tempting because sshd is the common remote login path, yet the policy must apply system-wide, not only to SSH sessions.
- ✗
/etc/pam.d/sudo with pam_permit.so
Why it's wrong here
pam_permit.so unconditionally allows access and performs no password checking whatsoever, so it cannot enforce length or character requirements. It is used for deliberately unrestricted services. Password complexity is enforced by pam_pwquality.so in the system password stack, not in sudo's authentication configuration.
- ✓
/etc/pam.d/common-password with pam_pwquality.so
Why this is correct
The pam_pwquality.so module enforces complexity rules through its ucredit, dcredit and minlen parameters, directly satisfying the policy's uppercase, digit and 12-character requirements. Placed in /etc/pam.d/common-password, it intercepts password changes via the password stack, rejecting non-compliant entries at update time.
Go deeper
Related to this question
Learn chapter
File Permissions and Ownership
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.