Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?

⚠ Common exam trap

XK0-006 often tests the difference between pam_faillock and pam_tally2, and candidates may choose the legacy command. The trap is to assume that pam_tally2 is still the standard for viewing failed attempts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

faillock --user username

The faillock command is the standard tool for viewing and managing failed login attempts when using pam_faillock. Running 'faillock --user username' displays the number of failed attempts and the timestamps for the specified user. This directly answers the question.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    faillock --user username

    Why this is correct

    The faillock utility reads the tally files that pam_faillock.so maintains and prints each user's recorded failure timestamps and count. Running it with --user username displays that account's failed attempts, letting the administrator confirm the lockout cause.

  • ✗

    ausearch -m USER_LOGIN -ui username

    Why it's wrong here

    ausearch queries the audit daemon's USER_LOGIN records, which capture audit events rather than pam_faillock's internal failure tally; the lockout counter lives in the faillock database, not audit logs. It is tempting where auditd is running, since audit records do show authentication attempts, but they do not reflect pam_faillock state.

  • ✗

    pam_tally2 --user username

    Why it's wrong here

    pam_tally2 belongs to the older pam_tally2 module, which stores counters in /var/log/tallylog; pam_faillock writes its per-user failure records to /var/run/faillock (or /var/log/faillock), so pam_tally2 reads the wrong store and reports nothing. It is tempting because it was the standard counter-inspection tool before pam_faillock replaced it.

  • ✗

    lastb username

    Why it's wrong here

    lastb reads the btmp login-failure record, which logs failed terminal and network logins, not PAM authentication counters; pam_faillock's tally is never written there. It is tempting because it lists failed logins by username, but it cannot report the faillock attempt count that triggers the lockout.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.