XK0-006 System Management Practice Question
An administrator wants to grant a specific user, 'jdoe', read and write access to a file that is owned by root:root with permissions 640. The administrator does not want to change the file's owner or group. Which approach should be used?
⚠ Common exam trap
XK0-006 often tests whether candidates reach for chmod or group membership when the requirement is per-user access without changing ownership — the trap is over-granting with 'o+rw' or 'add to root group'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use setfacl -m u:jdoe:rw file
POSIX ACLs allow granting permissions to specific users or groups without altering the file's owner or group. The command 'setfacl -m u:jdoe:rw file' adds an ACL entry giving jdoe read and write access while leaving root:root ownership and the 640 mode intact. This is the standard, least-disruptive approach for per-user access on a shared file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use setfacl -m u:jdoe:rw file
Why this is correct
setfacl -m u:jdoe:rw adds a named user entry to the file's access control list, granting jdoe read and write access. This satisfies the constraint of not altering the file's owner or group, which chmod and chown would change.
- ✗
Change file owner to jdoe
Why it's wrong here
Changing ownership to jdoe directly violates the stated constraint that owner and group remain root:root, and it strips root's control of the file. It is tempting as the obvious way to grant access, but an ACL entry grants jdoe read and write while preserving the existing ownership.
- ✗
Use chmod o+rw file
Why it's wrong here
Setting other-write grants access to every account on the system, not just jdoe, and still leaves the group unchanged. It is tempting because chmod modifies permissions without touching ownership, and it would be correct when all users genuinely require identical access to the file.
- ✗
Add jdoe to the root group
Why it's wrong here
Adding jdoe to root grants group read via the existing 640 bits, but group write is absent, so write access still fails; it also confers root-group privileges far beyond this file. A per-user ACL entry satisfies the read/write requirement without altering ownership or group.
Visual reference
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
setfacl
setfacl is a Linux/Unix command used to set Access Control Lists on files and directories, providing more detailed permission control beyond the standard owner-group-others model.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.