Courseiva
easyMultiple Choice

XK0-006 Practice Question: A user is unable to create new files in a…

A user is unable to create new files in a directory. Which command can the administrator use to view the Access Control Lists (ACLs) associated with that directory?

⚠ Common exam trap

Test-takers frequently confuse `ls -l` with ACL viewing, assuming the standard permission string (e.g., `drwxr-xr-x`) fully represents access rights, when in fact ACLs can override or extend those bits without changing the mode display.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

getfacl

The `getfacl` command displays the Access Control Lists (ACLs) for a file or directory, showing both the standard POSIX permissions and any additional ACL entries (e.g., specific users or groups). Since the user cannot create new files, ACLs may be restricting write access beyond the basic mode bits, making `getfacl` the correct tool to inspect these extended permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    getfacl

    Why this is correct

    `getfacl` reads and displays a file or directory's full ACL entries, including the owner, group, other permissions and any extended access control entries. Since the user cannot create files, inspecting those extended entries reveals whether write and execute permissions are missing for that user or group, which standard `ls -l` output cannot show.

  • ✗

    ls -l

    Why it's wrong here

    ls -l displays the standard mode bits, owner and group, but not extended POSIX ACL entries, so it cannot reveal the access rules blocking file creation. It is the correct choice when only traditional permissions need checking on a file or directory.

  • ✗

    setfacl

    Why it's wrong here

    setfacl modifies ACL entries; it writes or removes permissions rather than displaying them, so it cannot show the administrator the existing rules denying file creation. It is the right choice when granting or revoking specific user and group access on a directory.

  • ✗

    chmod

    Why it's wrong here

    chmod alters permission bits and symbolic modes; it cannot display ACL entries, so it fails to reveal the directory's ACLs. It is tempting because chmod manages file permissions, and would be correct when granting or revoking access rights, not when auditing them.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.