XK0-006 Security Practice Question
A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?
⚠ Common exam trap
The trap is mixing up the -l (lock) and -u (unlock) flags on passwd, or confusing password locking with account expiration via chage -E.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
passwd -u username
The passwd -u username command unlocks a previously locked user account by removing the leading '!' from the password hash in /etc/shadow. This is the direct counterpart to passwd -l, which locks the account by prepending '!' to the hash.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
usermod -L username
Why it's wrong here
usermod -L prefixes the password hash with an exclamation mark, locking the account further rather than unlocking it. It is tempting because usermod manages account state, but it would be correct when the requirement is to lock a password, not to reverse a lock.
- ✗
passwd -l username
Why it's wrong here
passwd -l also prefixes the hash with an exclamation mark, locking the password; it cannot remove an existing lock. It is tempting because passwd handles password state, but it would be correct when the requirement is to lock a password, not to unlock one.
- ✓
passwd -u username
Why this is correct
`passwd -u username` unlocks a password-locked account by clearing the lock flag in `/etc/shadow`, directly satisfying the stem's requirement to unlock the account. The `-u` flag reverses a prior `passwd -l`, restoring the user's ability to authenticate with their existing password.
- ✗
chage -E -1 username
Why it's wrong here
chage -E -1 clears the account-expiry date, which governs whether the account has expired, not whether the password is locked. It is tempting because chage manages account ageing, but it would be correct when the requirement is to remove an expiry date rather than unlock a password.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
passwd
passwd is a command-line utility used on Linux and Unix-like systems to change a user's password, typically stored in an encrypted format in the /etc/shadow file.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.