Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?

⚠ Common exam trap

The trap is mixing up the -l (lock) and -u (unlock) flags on passwd, or confusing password locking with account expiration via chage -E.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

passwd -u username

The passwd -u username command unlocks a previously locked user account by removing the leading '!' from the password hash in /etc/shadow. This is the direct counterpart to passwd -l, which locks the account by prepending '!' to the hash.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    usermod -L username

    Why it's wrong here

    usermod -L prefixes the password hash with an exclamation mark, locking the account further rather than unlocking it. It is tempting because usermod manages account state, but it would be correct when the requirement is to lock a password, not to reverse a lock.

  • ✗

    passwd -l username

    Why it's wrong here

    passwd -l also prefixes the hash with an exclamation mark, locking the password; it cannot remove an existing lock. It is tempting because passwd handles password state, but it would be correct when the requirement is to lock a password, not to unlock one.

  • ✓

    passwd -u username

    Why this is correct

    `passwd -u username` unlocks a password-locked account by clearing the lock flag in `/etc/shadow`, directly satisfying the stem's requirement to unlock the account. The `-u` flag reverses a prior `passwd -l`, restoring the user's ability to authenticate with their existing password.

  • ✗

    chage -E -1 username

    Why it's wrong here

    chage -E -1 clears the account-expiry date, which governs whether the account has expired, not whether the password is locked. It is tempting because chage manages account ageing, but it would be correct when the requirement is to remove an expiry date rather than unlock a password.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.