Courseiva
System Management →mediumMultiple Select

XK0-006 ACL (Access Control List) Practice Question

An administrator needs to grant read and write access to the 'developers' group on a directory while preserving existing permissions for the owner and others. Which TWO commands can be used to modify ACLs? (Choose two.)

⚠ Common exam trap

Candidates often confuse the user and group flags in setfacl. The -m option can specify either u: for user or g: for group. Ensure the correct entity type is used based on whether you need to assign permissions to a user or a group.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

setfacl -m g:developers:rw /dir

setfacl -m g:developers:rw /dir is the correct command to grant read-write access to the developers group. Option C uses u:developers, which sets an ACL for a user named 'developers', not the developers group, so it does not satisfy the requirement. chmod changes standard permissions, getfacl only displays ACLs, and setfacl -x removes ACL entries. Therefore, only option E is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    chmod g+rw /dir

    Why it's wrong here

    chmod changes standard file permissions (user/group/other), not ACL entries. It does not modify the full ACL structure, so it is incorrect.

  • ✗

    getfacl /dir

    Why it's wrong here

    getfacl displays ACLs but does not modify them. It is a read-only command.

  • ✗

    setfacl -m u:developers:rw /dir

    Why it's wrong here

    setfacl -m u:developers:rw sets an ACL entry for a user named 'developers'. If such a user exists, this grants them read and write access, effectively meeting the requirement. This is correct.

  • ✗

    setfacl -x g:developers /dir

    Why it's wrong here

    setfacl -x removes an ACL entry. It does not add or modify permissions, so it is incorrect.

  • ✓

    setfacl -m g:developers:rw /dir

    Why this is correct

    setfacl -m g:developers:rw sets an ACL entry for the 'developers' group, granting read and write access. This directly fulfills the requirement and is correct.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.