Courseiva

XK0-006 · domain

Security

The Security domain of CompTIA Linux+ XK0-006 covers host hardening and access control on Linux systems. Expect scenario questions on SELinux and AppArmor modes, user account and password aging with useradd, passwd, and chage, file permissions and ownership, sudo configuration, and SSH and firewall basics. Items ask you to pick the exact command or file that produces a described state.

109 questions24 easy54 medium31 hard

Focused practice

Practice Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security

Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.

Switching AppArmor profiles between complain and enforce mode with aa-complain and aa-enforce

Reading SELinux state with getenforce and sestatus, and adjusting it via setenforce or config files

Creating users with useradd, setting shells and home directories, and forcing password changes with chage

Managing sudo privileges, file ownership and permissions, and SSH or firewall access rules

Watch out for

Common Security exam traps

  • ▸Confusing SELinux and AppArmor tooling, or assuming setenforce changes persist across reboots when it only alters runtime mode
  • ▸Using usermod or passwd when the task actually requires chage to expire a password or set aging policy
  • ▸Forgetting that useradd alone does not set a password, so the account stays locked until passwd or chpasswd runs

Question index

All Security questions (109)

Click any question to see the full explanation, or start a practice session above.

1

A file named 'webapp.conf' is being served by Apache but users get a 'Permission denied' error. The SELinux context of the file is 'unconfined_u:object_r:admin_home_t:s0'. What is the most appropriate command to fix the SELinux context?

Hard
2

Which file contains the password aging information such as minimum and maximum days between password changes?

Easy
3

A security analyst needs to see a list of failed login attempts on a Linux system. Which command displays this information from the /var/log/btmp log?

Medium
4

A security policy requires that system logs be rotated weekly and kept for 4 weeks. Which configuration file should be modified to achieve this for /var/log/syslog?

Medium
5

A system administrator wants to limit the number of simultaneous logins for a user to 2. Which file and parameter should be configured?

Medium
6

A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?

Medium
7

A Linux server is configured with an IPsec VPN using strongSwan. The administrator needs to verify that the VPN tunnel is active and that traffic is being encrypted. Which command should be used to display the current status of the IPsec security associations?

Hard
8

A security analyst notices repeated failed login attempts on a Linux server. They want to lock the account after 3 failed attempts using PAM. Which PAM module should be configured in /etc/pam.d/sshd or /etc/pam.d/system-auth?

Medium
9

A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)

Hard
10

A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.

Hard
11

A Linux administrator is configuring a server to use firewalld. The administrator wants to allow incoming traffic on TCP port 8080 only from the 192.168.1.0/24 subnet, while denying it from all other sources, without affecting other services. Which firewalld command should the administrator use to achieve this?

Hard
12

An administrator needs to harden SSH access. Which TWO settings in /etc/ssh/sshd_config are recommended to improve security? (Choose two.)

Medium
13

A Linux administrator needs to ensure that all user passwords meet a minimum length of 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these password complexity requirements?

Easy
14

A Linux administrator needs to add a new user named 'jdoe' with a home directory and a bash shell. Which command accomplishes this?

Easy
15

An administrator needs to prevent a specific user 'bob' from logging in via SSH while allowing other users. Which configuration directive should be added to /etc/ssh/sshd_config?

Medium
16

An administrator wants to restrict SSH access to only users in the 'sshusers' group. Which configuration directive should be added to /etc/ssh/sshd_config?

Medium
17

A Linux administrator needs to grant a user the ability to run a specific command as root without being prompted for a password, while restricting all other commands. Which file should be edited to configure this using sudo?

Easy
18

A Linux administrator needs to grant the user 'jsmith' the ability to restart the httpd service without entering a password, while preventing all other sudo commands. The administrator creates the file /etc/sudoers.d/jsmith with the line: jsmith ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd. After saving the file, jsmith reports that sudo still prompts for a password. Which command should the administrator run to diagnose the issue?

Medium
19

A Linux server hosts a web application that must be able to bind to TCP port 443. The administrator has already installed the application and configured it to listen on 443. However, when the service starts, it fails with a 'Permission denied' error. The administrator confirms that no other process is using port 443 and that the service runs as the non-root user 'webapp'. Which command should the administrator use to grant the necessary capability to the service binary without giving it full root privileges?

Medium
20

An AppArmor profile for a web server is in complain mode. After testing, the administrator wants to enforce the profile. Which command accomplishes this?

Hard
21

A Linux administrator is configuring an SSH server to use certificate-based authentication. The administrator has generated a CA key pair and wants to sign a user's public key. Which command should be used to sign the user's public key with the CA and produce a certificate?

Hard
22

A security administrator is reviewing SSH configuration. Which TWO settings enhance security by limiting authentication attempts and preventing password-based logins? (Choose two.)

Medium
23

A security team wants to restrict SSH access to only users in the 'sshusers' group. Which configuration line in /etc/ssh/sshd_config achieves this?

Medium
24

A security team wants to harden a Linux server against unauthorized access. They need to restrict which users can authenticate via SSH and ensure that only key-based authentication is allowed for a specific group. Which TWO actions should the administrator take? (Choose two.)

Hard
25

A Linux administrator wants to prevent users from reusing their last five passwords. Which PAM module should be configured?

Easy
26

A junior administrator needs to check whether a user account named 'bob' is locked and view the password aging information. Which command should be used?

Easy
27

After configuring AppArmor, an administrator wants to verify the status of all profiles and switch a profile from complain to enforce mode. Which TWO commands are appropriate? (Choose two.)

Hard
28

A security audit reveals that users can change their password without meeting complexity requirements. Which PAM module should be configured to enforce password complexity?

Medium
29

A security analyst wants to ensure that users cannot change their password more than once every 7 days. Which command and option should be used to enforce this policy for user 'jsmith'?

Medium
30

A Linux administrator is configuring a server that must meet strict security guidelines. The server uses firewalld and should drop all incoming traffic on the public zone by default, but allow outgoing SSH connections initiated by the server itself to a remote management host. Which firewalld configuration should the administrator apply?

Hard
31

An administrator wants to force a password change for user 'alice' on next login. Which command is appropriate?

Easy
32

To limit the number of processes a user can create, which file should be configured?

Medium
33

A Linux administrator wants to allow the web server (httpd) to bind to a non-standard port, TCP 8080, without disabling SELinux. The system is running SELinux in enforcing mode. Which command should the administrator run to permanently allow httpd to listen on TCP port 8080?

Medium
34

A security engineer must ensure that a new SSH host key is generated using the Ed25519 algorithm and stored in the default location. Which command accomplishes this?

Hard
35

A system administrator needs to configure sudo so that members of the 'wheel' group can execute any command without a password. Which line should be added to /etc/sudoers (using visudo)?

Medium
36

A security audit reveals that an SELinux boolean 'httpd_can_network_connect' is currently off, but a web application requires Apache to connect to a database server. Which command should the administrator use to enable this boolean persistently?

Hard
37

Which command can be used to generate an SSH key pair for user authentication?

Easy
38

A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?

Medium
39

A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)

Medium
40

Which of the following correctly describes the purpose of the /etc/shadow file?

Easy
41

An administrator wants to enforce an account lockout policy after five failed login attempts on a Linux system. Which PAM module should be added to the authentication stack?

Easy
42

A system administrator configures PAM to enforce account lockout after 3 failed login attempts. Which PAM module should be used?

Hard
43

A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?

Medium
44

A Linux administrator needs to add a new user named 'jdoe' with a home directory and default shell /bin/bash. Which command should be used?

Easy
45

A security administrator is hardening a Linux server and wants to verify that the SSH daemon is configured to disallow direct root logins. The administrator has already edited /etc/ssh/sshd_config and set PermitRootLogin no. Which command should the administrator run to ensure the SSH daemon reloads the configuration without terminating existing SSH sessions?

Medium
46

An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?

Hard
47

A system administrator is hardening SSH and needs to disable root login and password authentication. Which two directives should be set in /etc/ssh/sshd_config?

Medium
48

An administrator wants to generate a self-signed certificate and private key for testing. Which command creates both in one step?

Medium
49

A system administrator needs to add an iptables rule to drop incoming TCP traffic on port 22 (SSH) from the IP address 10.0.0.100. Which command should be used?

Medium
50

A Linux administrator is troubleshooting a service that fails to start. The audit.log shows an AVC denial related to the httpd_t domain. The administrator wants to see the full denial message and generate a policy to allow the access. Which two commands should be used in conjunction?

Medium
51

An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?

Hard
52

An administrator is troubleshooting an AppArmor profile that is blocking a custom application. They want to set the profile to complain mode to gather violations without enforcing. Which command should they use?

Hard
53

A security audit has identified that several users have excessive sudo privileges. The administrator needs to review and modify sudo access. Which two files or commands would be used? (Choose TWO.)

Medium
54

To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?

Medium
55

A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?

Medium
56

A security audit reveals that a service is running with an incorrect SELinux context. Which two commands can be used to relabel the file or directory to the correct context? (Choose TWO.)

Hard
57

A security administrator needs to configure a Linux server so that all users must use a password of at least 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these requirements?

Medium
58

A Linux administrator needs to prevent the root user from logging in via SSH. Which directive should be set in /etc/ssh/sshd_config to accomplish this?

Easy
59

A web server running on port 8080 must be accessible from external networks. The system uses firewalld. Which command opens port 8080/tcp permanently in the default zone?

Medium
60

A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?

Medium
61

A Linux administrator needs to ensure that user passwords meet a minimum length requirement of 12 characters. The system uses PAM and the pam_pwquality module. Which file should the administrator edit to set the minlen parameter?

Easy
62

A technician needs to ensure a service can listen on TCP port 8443 using firewalld. Which command permanently adds the port to the default zone?

Easy
63

A Linux administrator is implementing mandatory access control using AppArmor on an Ubuntu server. A custom web application profile is loaded in enforce mode, but the application is failing to write to /var/log/myapp/. The administrator wants to temporarily switch the profile to complain mode to diagnose the issue without disabling AppArmor entirely. Which command should be used?

Hard
64

An administrator runs 'auditctl -w /etc/passwd -p wa -k passwd_changes' to monitor changes to /etc/passwd. Which command should be used to search the audit log for all events related to this watch?

Hard
65

A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)

Medium
66

An administrator wants to harden SSH access by implementing the following: disallow root login, disable password authentication, and limit the number of authentication attempts. Which three configuration directives should be set in /etc/ssh/sshd_config? (Choose THREE.)

Medium
67

An administrator notices repeated failed login attempts in /var/log/secure. The company policy requires account lockout after 5 failed attempts within 15 minutes. Which PAM module and configuration can enforce this?

Medium
68

A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?

Hard
69

A Linux administrator needs to add a new user named 'jdoe' with a home directory and bash shell. Which command accomplishes this?

Easy
70

A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?

Medium
71

An administrator is hardening SSH and wants to disable root login and only allow users in the 'sshusers' group. Which two directives should be set in /etc/ssh/sshd_config?

Medium
72

Which file contains user password hashes and aging information on a Linux system?

Easy
73

A security policy requires that user passwords must be changed every 60 days, and users should be warned 7 days before expiration. Which two chage commands set these requirements for user 'jsmith'? (Choose TWO.)

Medium
74

A Linux administrator needs to configure the system so that all users must use a minimum password length of 12 characters. The administrator edits /etc/security/pwquality.conf. Which line should be added or modified to enforce this requirement?

Easy
75

A Linux server has SELinux enforcing and a custom application needs to write to /var/log/app.log. The audit log shows 'avc: denied { write } for pid=1234'. After verifying that the application runs in the correct domain, which command should be used to allow the write access by generating a policy module?

Hard
76

A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?

Medium
77

A Linux administrator is configuring a server to use a centralized authentication service. The security policy requires that user credentials are never sent in clear text and that the authentication traffic is encrypted. The administrator decides to use LDAP with TLS. Which command should be used to verify that the LDAP server's certificate is valid and that the TLS handshake succeeds?

Medium
78

An administrator needs to ensure that only users from the 'ops' group can SSH into a server. Which configuration in /etc/ssh/sshd_config accomplishes this?

Hard
79

An administrator notices that a custom application uses port 8443/TCP. To allow external access, which firewalld command permanently opens this port in the default zone?

Hard
80

A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?

Easy
81

A system administrator wants to enforce a password policy requiring a minimum length of 12 characters, at least one uppercase letter, and one digit. Which PAM module should be configured?

Easy
82

An administrator needs to view all current nftables rules. Which command should be used?

Hard
83

An administrator is configuring iptables on a server. The requirements are: allow incoming SSH (port 22) from the 192.168.1.0/24 network, drop all other incoming traffic, and allow all outgoing traffic. Which three iptables rules achieve this? (Choose THREE.)

Hard
84

A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?

Medium
85

An administrator needs to generate a self-signed certificate valid for 365 days with a 2048-bit RSA key. Which OpenSSL command correctly creates both the private key and certificate in one step?

Hard
86

A Linux administrator wants to harden a server against brute-force attacks. They decide to use fail2ban to monitor SSH authentication failures. After installing and enabling the fail2ban service, they need to verify that the SSH jail is active and correctly configured. Which command should they use to check the current status of the sshd jail?

Medium
87

An administrator wants to allow the user 'ops' to run only the command '/usr/bin/systemctl restart httpd' via sudo on a specific host 'webserver'. Which /etc/sudoers entry is correct?

Hard
88

Which file contains the hashed passwords and password aging information for user accounts?

Easy
89

A Linux engineer needs to harden SSH access. Which TWO of the following settings should be configured in /etc/ssh/sshd_config to enhance security? (Select TWO.)

Medium
90

A Linux administrator is configuring a system to use a centralized authentication service. The requirement is that if the central server is unreachable, users should still be able to log in using cached credentials. Which PAM module should be configured to provide this functionality?

Hard
91

A Linux administrator needs to configure sudo access for members of the 'wheel' group to run any command. Which two steps are required? (Choose TWO.)

Medium
92

An administrator needs to generate a self-signed certificate and private key for an internal web server. Which OpenSSL command creates both in one step?

Hard
93

An administrator configures /etc/ssh/sshd_config with the following settings: PermitRootLogin no, PasswordAuthentication no, AllowUsers alice bob, MaxAuthTries 2. After restarting sshd, which of the following is true?

Hard
94

SELinux is currently in enforcing mode. A service is being blocked by SELinux. Which command can analyze the audit log and suggest the minimum policy changes to allow the service?

Medium
95

A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?

Hard
96

A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?

Medium
97

An administrator needs to generate a self-signed certificate and private key for a web server. Which openssl command accomplishes this?

Medium
98

Which log file typically records authentication failures and successes on a Debian-based system?

Easy
99

Which command displays the current SELinux mode?

Easy
100

A Linux administrator needs to grant a user named 'bob' the ability to run the /usr/bin/systemctl command as root without being prompted for a password. Which entry should be added to the sudoers file to accomplish this?

Easy
101

A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)

Medium
102

A security audit reveals that the system's PAM configuration does not enforce password complexity. Which PAM module and configuration line should be added to /etc/pam.d/common-password to require at least one uppercase letter, one digit, and a minimum length of 12 characters?

Medium
103

Which THREE are valid SELinux modes?

Medium
104

A security analyst is investigating a potential breach and needs to examine user login history. Which THREE commands or log files provide information about user logins? (Select THREE.)

Medium
105

A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?

Medium
106

An administrator wants to ensure that only users in the 'wheel' group can use the sudo command. Which directive in /etc/sudoers enables this?

Easy
107

An administrator needs to configure SELinux to allow the Apache HTTP server to connect to a database server. Which SELinux boolean should be enabled?

Medium
108

A Linux engineer needs to restrict resource usage for users in the 'developers' group. Which TWO files or commands can be used to set ulimit values?

Medium
109

A compliance auditor requires that a Linux server's /home directory be mounted with options that prevent users from executing setuid binaries stored there and from creating device files. The administrator is editing /etc/fstab for the /home entry. Which TWO mount options should be added to meet these requirements? (Choose two.)

Medium

Frequently asked questions

What does the Security domain cover on the XK0-006 exam?
Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.
How many questions are in this domain?
This page lists all 109 Security questions in the XK0-006 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
linux-plus LINUX-PLUS lxp security Practice Questions