XK0-006 · domain
Security
The Security domain of CompTIA Linux+ XK0-006 covers host hardening and access control on Linux systems. Expect scenario questions on SELinux and AppArmor modes, user account and password aging with useradd, passwd, and chage, file permissions and ownership, sudo configuration, and SSH and firewall basics. Items ask you to pick the exact command or file that produces a described state.
Focused practice
Practice Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security
Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.
Switching AppArmor profiles between complain and enforce mode with aa-complain and aa-enforce
Reading SELinux state with getenforce and sestatus, and adjusting it via setenforce or config files
Creating users with useradd, setting shells and home directories, and forcing password changes with chage
Watch out for
Common Security exam traps
- ▸Confusing SELinux and AppArmor tooling, or assuming setenforce changes persist across reboots when it only alters runtime mode
- ▸Using usermod or passwd when the task actually requires chage to expire a password or set aging policy
- ▸Forgetting that useradd alone does not set a password, so the account stays locked until passwd or chpasswd runs
Question index
All Security questions (109)
Click any question to see the full explanation, or start a practice session above.
A file named 'webapp.conf' is being served by Apache but users get a 'Permission denied' error. The SELinux context of the file is 'unconfined_u:object_r:admin_home_t:s0'. What is the most appropriate command to fix the SELinux context?
Hard2Which file contains the password aging information such as minimum and maximum days between password changes?
Easy3A security analyst needs to see a list of failed login attempts on a Linux system. Which command displays this information from the /var/log/btmp log?
Medium4A security policy requires that system logs be rotated weekly and kept for 4 weeks. Which configuration file should be modified to achieve this for /var/log/syslog?
Medium5A system administrator wants to limit the number of simultaneous logins for a user to 2. Which file and parameter should be configured?
Medium6A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?
Medium7A Linux server is configured with an IPsec VPN using strongSwan. The administrator needs to verify that the VPN tunnel is active and that traffic is being encrypted. Which command should be used to display the current status of the IPsec security associations?
Hard8A security analyst notices repeated failed login attempts on a Linux server. They want to lock the account after 3 failed attempts using PAM. Which PAM module should be configured in /etc/pam.d/sshd or /etc/pam.d/system-auth?
Medium9A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)
Hard10A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.
Hard11A Linux administrator is configuring a server to use firewalld. The administrator wants to allow incoming traffic on TCP port 8080 only from the 192.168.1.0/24 subnet, while denying it from all other sources, without affecting other services. Which firewalld command should the administrator use to achieve this?
Hard12An administrator needs to harden SSH access. Which TWO settings in /etc/ssh/sshd_config are recommended to improve security? (Choose two.)
Medium13A Linux administrator needs to ensure that all user passwords meet a minimum length of 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these password complexity requirements?
Easy14A Linux administrator needs to add a new user named 'jdoe' with a home directory and a bash shell. Which command accomplishes this?
Easy15An administrator needs to prevent a specific user 'bob' from logging in via SSH while allowing other users. Which configuration directive should be added to /etc/ssh/sshd_config?
Medium16An administrator wants to restrict SSH access to only users in the 'sshusers' group. Which configuration directive should be added to /etc/ssh/sshd_config?
Medium17A Linux administrator needs to grant a user the ability to run a specific command as root without being prompted for a password, while restricting all other commands. Which file should be edited to configure this using sudo?
Easy18A Linux administrator needs to grant the user 'jsmith' the ability to restart the httpd service without entering a password, while preventing all other sudo commands. The administrator creates the file /etc/sudoers.d/jsmith with the line: jsmith ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd. After saving the file, jsmith reports that sudo still prompts for a password. Which command should the administrator run to diagnose the issue?
Medium19A Linux server hosts a web application that must be able to bind to TCP port 443. The administrator has already installed the application and configured it to listen on 443. However, when the service starts, it fails with a 'Permission denied' error. The administrator confirms that no other process is using port 443 and that the service runs as the non-root user 'webapp'. Which command should the administrator use to grant the necessary capability to the service binary without giving it full root privileges?
Medium20An AppArmor profile for a web server is in complain mode. After testing, the administrator wants to enforce the profile. Which command accomplishes this?
Hard21A Linux administrator is configuring an SSH server to use certificate-based authentication. The administrator has generated a CA key pair and wants to sign a user's public key. Which command should be used to sign the user's public key with the CA and produce a certificate?
Hard22A security administrator is reviewing SSH configuration. Which TWO settings enhance security by limiting authentication attempts and preventing password-based logins? (Choose two.)
Medium23A security team wants to restrict SSH access to only users in the 'sshusers' group. Which configuration line in /etc/ssh/sshd_config achieves this?
Medium24A security team wants to harden a Linux server against unauthorized access. They need to restrict which users can authenticate via SSH and ensure that only key-based authentication is allowed for a specific group. Which TWO actions should the administrator take? (Choose two.)
Hard25A Linux administrator wants to prevent users from reusing their last five passwords. Which PAM module should be configured?
Easy26A junior administrator needs to check whether a user account named 'bob' is locked and view the password aging information. Which command should be used?
Easy27After configuring AppArmor, an administrator wants to verify the status of all profiles and switch a profile from complain to enforce mode. Which TWO commands are appropriate? (Choose two.)
Hard28A security audit reveals that users can change their password without meeting complexity requirements. Which PAM module should be configured to enforce password complexity?
Medium29A security analyst wants to ensure that users cannot change their password more than once every 7 days. Which command and option should be used to enforce this policy for user 'jsmith'?
Medium30A Linux administrator is configuring a server that must meet strict security guidelines. The server uses firewalld and should drop all incoming traffic on the public zone by default, but allow outgoing SSH connections initiated by the server itself to a remote management host. Which firewalld configuration should the administrator apply?
Hard31An administrator wants to force a password change for user 'alice' on next login. Which command is appropriate?
Easy32To limit the number of processes a user can create, which file should be configured?
Medium33A Linux administrator wants to allow the web server (httpd) to bind to a non-standard port, TCP 8080, without disabling SELinux. The system is running SELinux in enforcing mode. Which command should the administrator run to permanently allow httpd to listen on TCP port 8080?
Medium34A security engineer must ensure that a new SSH host key is generated using the Ed25519 algorithm and stored in the default location. Which command accomplishes this?
Hard35A system administrator needs to configure sudo so that members of the 'wheel' group can execute any command without a password. Which line should be added to /etc/sudoers (using visudo)?
Medium36A security audit reveals that an SELinux boolean 'httpd_can_network_connect' is currently off, but a web application requires Apache to connect to a database server. Which command should the administrator use to enable this boolean persistently?
Hard37Which command can be used to generate an SSH key pair for user authentication?
Easy38A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?
Medium39A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)
Medium40Which of the following correctly describes the purpose of the /etc/shadow file?
Easy41An administrator wants to enforce an account lockout policy after five failed login attempts on a Linux system. Which PAM module should be added to the authentication stack?
Easy42A system administrator configures PAM to enforce account lockout after 3 failed login attempts. Which PAM module should be used?
Hard43A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?
Medium44A Linux administrator needs to add a new user named 'jdoe' with a home directory and default shell /bin/bash. Which command should be used?
Easy45A security administrator is hardening a Linux server and wants to verify that the SSH daemon is configured to disallow direct root logins. The administrator has already edited /etc/ssh/sshd_config and set PermitRootLogin no. Which command should the administrator run to ensure the SSH daemon reloads the configuration without terminating existing SSH sessions?
Medium46An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?
Hard47A system administrator is hardening SSH and needs to disable root login and password authentication. Which two directives should be set in /etc/ssh/sshd_config?
Medium48An administrator wants to generate a self-signed certificate and private key for testing. Which command creates both in one step?
Medium49A system administrator needs to add an iptables rule to drop incoming TCP traffic on port 22 (SSH) from the IP address 10.0.0.100. Which command should be used?
Medium50A Linux administrator is troubleshooting a service that fails to start. The audit.log shows an AVC denial related to the httpd_t domain. The administrator wants to see the full denial message and generate a policy to allow the access. Which two commands should be used in conjunction?
Medium51An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?
Hard52An administrator is troubleshooting an AppArmor profile that is blocking a custom application. They want to set the profile to complain mode to gather violations without enforcing. Which command should they use?
Hard53A security audit has identified that several users have excessive sudo privileges. The administrator needs to review and modify sudo access. Which two files or commands would be used? (Choose TWO.)
Medium54To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?
Medium55A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?
Medium56A security audit reveals that a service is running with an incorrect SELinux context. Which two commands can be used to relabel the file or directory to the correct context? (Choose TWO.)
Hard57A security administrator needs to configure a Linux server so that all users must use a password of at least 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these requirements?
Medium58A Linux administrator needs to prevent the root user from logging in via SSH. Which directive should be set in /etc/ssh/sshd_config to accomplish this?
Easy59A web server running on port 8080 must be accessible from external networks. The system uses firewalld. Which command opens port 8080/tcp permanently in the default zone?
Medium60A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?
Medium61A Linux administrator needs to ensure that user passwords meet a minimum length requirement of 12 characters. The system uses PAM and the pam_pwquality module. Which file should the administrator edit to set the minlen parameter?
Easy62A technician needs to ensure a service can listen on TCP port 8443 using firewalld. Which command permanently adds the port to the default zone?
Easy63A Linux administrator is implementing mandatory access control using AppArmor on an Ubuntu server. A custom web application profile is loaded in enforce mode, but the application is failing to write to /var/log/myapp/. The administrator wants to temporarily switch the profile to complain mode to diagnose the issue without disabling AppArmor entirely. Which command should be used?
Hard64An administrator runs 'auditctl -w /etc/passwd -p wa -k passwd_changes' to monitor changes to /etc/passwd. Which command should be used to search the audit log for all events related to this watch?
Hard65A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)
Medium66An administrator wants to harden SSH access by implementing the following: disallow root login, disable password authentication, and limit the number of authentication attempts. Which three configuration directives should be set in /etc/ssh/sshd_config? (Choose THREE.)
Medium67An administrator notices repeated failed login attempts in /var/log/secure. The company policy requires account lockout after 5 failed attempts within 15 minutes. Which PAM module and configuration can enforce this?
Medium68A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?
Hard69A Linux administrator needs to add a new user named 'jdoe' with a home directory and bash shell. Which command accomplishes this?
Easy70A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?
Medium71An administrator is hardening SSH and wants to disable root login and only allow users in the 'sshusers' group. Which two directives should be set in /etc/ssh/sshd_config?
Medium72Which file contains user password hashes and aging information on a Linux system?
Easy73A security policy requires that user passwords must be changed every 60 days, and users should be warned 7 days before expiration. Which two chage commands set these requirements for user 'jsmith'? (Choose TWO.)
Medium74A Linux administrator needs to configure the system so that all users must use a minimum password length of 12 characters. The administrator edits /etc/security/pwquality.conf. Which line should be added or modified to enforce this requirement?
Easy75A Linux server has SELinux enforcing and a custom application needs to write to /var/log/app.log. The audit log shows 'avc: denied { write } for pid=1234'. After verifying that the application runs in the correct domain, which command should be used to allow the write access by generating a policy module?
Hard76A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?
Medium77A Linux administrator is configuring a server to use a centralized authentication service. The security policy requires that user credentials are never sent in clear text and that the authentication traffic is encrypted. The administrator decides to use LDAP with TLS. Which command should be used to verify that the LDAP server's certificate is valid and that the TLS handshake succeeds?
Medium78An administrator needs to ensure that only users from the 'ops' group can SSH into a server. Which configuration in /etc/ssh/sshd_config accomplishes this?
Hard79An administrator notices that a custom application uses port 8443/TCP. To allow external access, which firewalld command permanently opens this port in the default zone?
Hard80A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?
Easy81A system administrator wants to enforce a password policy requiring a minimum length of 12 characters, at least one uppercase letter, and one digit. Which PAM module should be configured?
Easy82An administrator needs to view all current nftables rules. Which command should be used?
Hard83An administrator is configuring iptables on a server. The requirements are: allow incoming SSH (port 22) from the 192.168.1.0/24 network, drop all other incoming traffic, and allow all outgoing traffic. Which three iptables rules achieve this? (Choose THREE.)
Hard84A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?
Medium85An administrator needs to generate a self-signed certificate valid for 365 days with a 2048-bit RSA key. Which OpenSSL command correctly creates both the private key and certificate in one step?
Hard86A Linux administrator wants to harden a server against brute-force attacks. They decide to use fail2ban to monitor SSH authentication failures. After installing and enabling the fail2ban service, they need to verify that the SSH jail is active and correctly configured. Which command should they use to check the current status of the sshd jail?
Medium87An administrator wants to allow the user 'ops' to run only the command '/usr/bin/systemctl restart httpd' via sudo on a specific host 'webserver'. Which /etc/sudoers entry is correct?
Hard88Which file contains the hashed passwords and password aging information for user accounts?
Easy89A Linux engineer needs to harden SSH access. Which TWO of the following settings should be configured in /etc/ssh/sshd_config to enhance security? (Select TWO.)
Medium90A Linux administrator is configuring a system to use a centralized authentication service. The requirement is that if the central server is unreachable, users should still be able to log in using cached credentials. Which PAM module should be configured to provide this functionality?
Hard91A Linux administrator needs to configure sudo access for members of the 'wheel' group to run any command. Which two steps are required? (Choose TWO.)
Medium92An administrator needs to generate a self-signed certificate and private key for an internal web server. Which OpenSSL command creates both in one step?
Hard93An administrator configures /etc/ssh/sshd_config with the following settings: PermitRootLogin no, PasswordAuthentication no, AllowUsers alice bob, MaxAuthTries 2. After restarting sshd, which of the following is true?
Hard94SELinux is currently in enforcing mode. A service is being blocked by SELinux. Which command can analyze the audit log and suggest the minimum policy changes to allow the service?
Medium95A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?
Hard96A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?
Medium97An administrator needs to generate a self-signed certificate and private key for a web server. Which openssl command accomplishes this?
Medium98Which log file typically records authentication failures and successes on a Debian-based system?
Easy99Which command displays the current SELinux mode?
Easy100A Linux administrator needs to grant a user named 'bob' the ability to run the /usr/bin/systemctl command as root without being prompted for a password. Which entry should be added to the sudoers file to accomplish this?
Easy101A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)
Medium102A security audit reveals that the system's PAM configuration does not enforce password complexity. Which PAM module and configuration line should be added to /etc/pam.d/common-password to require at least one uppercase letter, one digit, and a minimum length of 12 characters?
Medium103Which THREE are valid SELinux modes?
Medium104A security analyst is investigating a potential breach and needs to examine user login history. Which THREE commands or log files provide information about user logins? (Select THREE.)
Medium105A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?
Medium106An administrator wants to ensure that only users in the 'wheel' group can use the sudo command. Which directive in /etc/sudoers enables this?
Easy107An administrator needs to configure SELinux to allow the Apache HTTP server to connect to a database server. Which SELinux boolean should be enabled?
Medium108A Linux engineer needs to restrict resource usage for users in the 'developers' group. Which TWO files or commands can be used to set ulimit values?
Medium109A compliance auditor requires that a Linux server's /home directory be mounted with options that prevent users from executing setuid binaries stored there and from creating device files. The administrator is editing /etc/fstab for the /home entry. Which TWO mount options should be added to meet these requirements? (Choose two.)
MediumOther domains
All XK0-006 exam domains
Frequently asked questions
- What does the Security domain cover on the XK0-006 exam?
- Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.
- How many questions are in this domain?
- This page lists all 109 Security questions in the XK0-006 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.