XK0-006 Security Practice Question
A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?
⚠ Common exam trap
XK0-006 often tests the confusion between account lockout modules (pam_faillock, pam_tally2) and password history modules (pam_pwhistory), so candidates must map 'reuse' to remember, not deny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pam_pwhistory with remember=5
The pam_pwhistory module records previous password hashes and enforces password reuse restrictions via the remember directive. Setting remember=5 prevents users from reusing any of their last five passwords, exactly matching the policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pam_faillock with deny=5
Why it's wrong here
pam_faillock with deny=5 locks an account after five failed login attempts, addressing brute-force authentication rather than password history. It would correctly throttle repeated wrong passwords, but it keeps no record of prior password hashes, so reuse of an old password is never detected.
- ✓
pam_pwhistory with remember=5
Why this is correct
`pam_pwhistory` stores previous password hashes in `/etc/security/opasswd` and compares each new password against them, rejecting any match. The `remember=5` directive retains the last five hashes, directly satisfying the policy's no-reuse constraint for the previous five passwords.
- ✗
pam_tally2 with deny=5
Why it's wrong here
pam_tally2 counts failed authentication attempts and locks accounts after a threshold; deny=5 sets that lockout count, not a password history. It would be the right choice for blocking brute-force logins, but it never inspects or stores previous password hashes.
- ✗
pam_pwquality with remember=5
Why it's wrong here
pam_pwquality enforces complexity and length, not password history; its remember directive is not the mechanism for blocking reuse. pam_pwhistory with remember=5 stores previous hashes and rejects reuse. pwquality tempts because it also accepts a remember argument, but that argument does not provide history enforcement.
Go deeper
Related to this question
Learn chapter
Networking Fundamentals and Configuration
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.