XK0-006 Security Practice Question
A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?
⚠ Common exam trap
XK0-006 often tests the difference between pam_faillock and pam_tally2, and candidates may choose the legacy command. The trap is to assume that pam_tally2 is still the standard for viewing failed attempts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
faillock --user username
The faillock command is the standard tool for viewing and managing failed login attempts when using pam_faillock. Running 'faillock --user username' displays the number of failed attempts and the timestamps for the specified user. This directly answers the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
faillock --user username
Why this is correct
The faillock utility reads the tally files that pam_faillock.so maintains and prints each user's recorded failure timestamps and count. Running it with --user username displays that account's failed attempts, letting the administrator confirm the lockout cause.
- ✗
ausearch -m USER_LOGIN -ui username
Why it's wrong here
ausearch queries the audit daemon's USER_LOGIN records, which capture audit events rather than pam_faillock's internal failure tally; the lockout counter lives in the faillock database, not audit logs. It is tempting where auditd is running, since audit records do show authentication attempts, but they do not reflect pam_faillock state.
- ✗
pam_tally2 --user username
Why it's wrong here
pam_tally2 belongs to the older pam_tally2 module, which stores counters in /var/log/tallylog; pam_faillock writes its per-user failure records to /var/run/faillock (or /var/log/faillock), so pam_tally2 reads the wrong store and reports nothing. It is tempting because it was the standard counter-inspection tool before pam_faillock replaced it.
- ✗
lastb username
Why it's wrong here
lastb reads the btmp login-failure record, which logs failed terminal and network logins, not PAM authentication counters; pam_faillock's tally is never written there. It is tempting because it lists failed logins by username, but it cannot report the faillock attempt count that triggers the lockout.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.