Courseiva
System Management →mediumMultiple Choice

XK0-006 System Management Practice Question

An administrator wants to grant a specific user, 'jdoe', read and write access to a file that is owned by root:root with permissions 640. The administrator does not want to change the file's owner or group. Which approach should be used?

⚠ Common exam trap

XK0-006 often tests whether candidates reach for chmod or group membership when the requirement is per-user access without changing ownership — the trap is over-granting with 'o+rw' or 'add to root group'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use setfacl -m u:jdoe:rw file

POSIX ACLs allow granting permissions to specific users or groups without altering the file's owner or group. The command 'setfacl -m u:jdoe:rw file' adds an ACL entry giving jdoe read and write access while leaving root:root ownership and the 640 mode intact. This is the standard, least-disruptive approach for per-user access on a shared file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use setfacl -m u:jdoe:rw file

    Why this is correct

    setfacl -m u:jdoe:rw adds a named user entry to the file's access control list, granting jdoe read and write access. This satisfies the constraint of not altering the file's owner or group, which chmod and chown would change.

  • ✗

    Change file owner to jdoe

    Why it's wrong here

    Changing ownership to jdoe directly violates the stated constraint that owner and group remain root:root, and it strips root's control of the file. It is tempting as the obvious way to grant access, but an ACL entry grants jdoe read and write while preserving the existing ownership.

  • ✗

    Use chmod o+rw file

    Why it's wrong here

    Setting other-write grants access to every account on the system, not just jdoe, and still leaves the group unchanged. It is tempting because chmod modifies permissions without touching ownership, and it would be correct when all users genuinely require identical access to the file.

  • ✗

    Add jdoe to the root group

    Why it's wrong here

    Adding jdoe to root grants group read via the existing 640 bits, but group write is absent, so write access still fails; it also confers root-group privileges far beyond this file. A per-user ACL entry satisfies the read/write requirement without altering ownership or group.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.