Courseiva

CCNA Security Questions

75 of 109 questions · Page 1/2 · Security · Answers revealed

1
MCQhard

A file named 'webapp.conf' is being served by Apache but users get a 'Permission denied' error. The SELinux context of the file is 'unconfined_u:object_r:admin_home_t:s0'. What is the most appropriate command to fix the SELinux context?

A.semanage fcontext -a -t httpd_sys_content_t webapp.conf && restorecon -v webapp.conf
B.setenforce 0
C.chcon -t httpd_sys_content_t webapp.conf
D.restorecon -v webapp.conf
AnswerA

The file carries the admin_home_t type, which Apache's httpd_t domain cannot read, causing the denial. `semanage fcontext -a -t httpd_sys_content_t` adds a persistent mapping in the file-context policy, and `restorecon` applies it to webapp.conf, satisfying the requirement that the file hold the httpd content type.

Why this answer

The most appropriate command. It adds a persistent SELinux file context rule with semanage fcontext and then applies it with restorecon, ensuring the correct type (httpd_sys_content_t) is set and preserved across system relabeling. Option D (restorecon alone) may not work if the file's path lacks a default mapping in the SELinux policy, making it unreliable for non-standard locations.

Therefore, only A fully addresses the requirement for a permanent and reliable fix.

Exam trap

The trap is that candidates often choose chcon (option C) because it works immediately without additional commands. However, chcon changes are not persistent across file relabeling (e.g., after a full restorecon or system policy update), making semanage fcontext the recommended approach for a permanent fix.

How to eliminate wrong answers

Option B is wrong because 'setenforce 0' disables SELinux entirely, which is a security risk and not a proper fix for the context mismatch; it only masks the issue. Option C is wrong because 'chcon -t httpd_sys_content_t webapp.conf' changes the context temporarily but does not update the SELinux policy database, so the change will be lost after a file system relabel or 'restorecon' run. Option D is wrong because 'restorecon -v webapp.conf' alone will reset the file to its default context based on the current policy, but since no persistent rule exists for this file, it will revert to 'admin_home_t' (or another default) and not fix the permission error.

2
MCQeasy

Which file contains the password aging information such as minimum and maximum days between password changes?

A./etc/shadow
B./etc/security/limits.conf
C./etc/passwd
D./etc/login.defs
AnswerA

/etc/shadow stores per-user password aging fields, including minimum days, maximum days, warning period and expiry, alongside the hashed password. This directly satisfies the stem's requirement for minimum and maximum days between password changes, unlike /etc/passwd, which holds account data but no aging constraints.

Why this answer

The /etc/shadow file stores encrypted password hashes along with password aging fields: the date of last password change, minimum days before change allowed, maximum days the password is valid, warning days before expiration, inactivity days, and account expiration date. These aging parameters are set by chage or passwd and are enforced by PAM. /etc/passwd no longer stores password hashes on modern systems and does not contain aging fields.

Exam trap

XK0-006 often tests the confusion between /etc/login.defs (system-wide defaults for new accounts) and /etc/shadow (per-user actual aging data), causing candidates to pick login.defs when the question asks where the aging information is stored.

How to eliminate wrong answers

Option B is wrong because /etc/security/limits.conf defines resource limits (e.g., max open files, max processes) for users and groups via PAM's pam_limits module — it has nothing to do with password aging. Option C is wrong because /etc/passwd contains user account information (username, UID, GID, GECOS, home directory, shell) and historically the password hash, but on modern systems the password field is 'x' and aging data is not present there. Option D is wrong because /etc/login.defs contains system-wide defaults for useradd and password policies (e.g., PASS_MAX_DAYS, PASS_MIN_DAYS, PASS_WARN_AGE), but it holds defaults applied at account creation, not the per-user aging information itself — the question asks for the file containing the aging information, which is /etc/shadow.

3
MCQmedium

A security analyst needs to see a list of failed login attempts on a Linux system. Which command displays this information from the /var/log/btmp log?

A.lastb
B.lastlog
C.last
D.faillog
AnswerA

`lastb` reads the binary `/var/log/btmp` record file and prints each failed login attempt with its timestamp, source host and username. Since the stem explicitly requires displaying failed logins from that specific log, `lastb` is the matching tool; `last` reads `/var/log/wtmp` for successful sessions instead.

Why this answer

The `lastb` command reads the `/var/log/btmp` file, which specifically records failed login attempts. It displays a list of bad logins, including the username, terminal, source IP, and timestamp. This is the correct tool for auditing failed authentication events on Linux.

Exam trap

The trap here is confusing the four similar-sounding commands: `lastb` (failed logins from btmp), `lastlog` (last successful login per user from lastlog), `last` (successful login history from wtmp), and `faillog` (failed login counts from faillog). Candidates often mix up `lastb` and `faillog` because both relate to failures, but only `lastb` reads btmp.

How to eliminate wrong answers

Option B is wrong because `lastlog` reads `/var/log/lastlog` and shows the most recent successful login for each user, not failed attempts. Option C is wrong because `last` reads `/var/log/wtmp` and displays successful login history, including logins, logouts, and system reboots. Option D is wrong because `faillog` reads `/var/log/faillog` and shows failed login counts and lockout information per user, but it does not list individual failed attempts from btmp.

4
MCQmedium

A security policy requires that system logs be rotated weekly and kept for 4 weeks. Which configuration file should be modified to achieve this for /var/log/syslog?

A./etc/security/limits.conf
B./etc/rsyslog.conf
C./etc/logrotate.conf
D./etc/audit/auditd.conf
AnswerC

Editing /etc/logrotate.conf sets global rotation defaults, where the weekly directive satisfies the seven-day rotation constraint and rotate 4 retains four weeks of archives before deletion. Per-service overrides belong in /etc/logrotate.d/, but the stem asks which file governs rotation policy, making this the correct target.

Why this answer

Log rotation is managed by logrotate, not by rsyslog or syslog itself. The /etc/logrotate.conf file contains global rotation settings, including frequency (weekly) and retention count (rotate 4). Adding or modifying a configuration block for /var/log/syslog in logrotate.conf (or a file in /etc/logrotate.d/) directly implements the policy requirement.

Exam trap

CompTIA often tests the distinction between log generation (rsyslog.conf) and log rotation (logrotate.conf), so candidates mistakenly choose /etc/rsyslog.conf because they associate it with log management, not realizing rotation is a separate function.

How to eliminate wrong answers

Option A is wrong because /etc/security/limits.conf controls system resource limits (e.g., file handles, processes) per user via PAM, not log rotation. Option B is wrong because /etc/rsyslog.conf configures the rsyslog daemon’s logging rules, outputs, and facilities, but does not handle rotation or retention of log files. Option D is wrong because /etc/audit/auditd.conf configures the audit daemon (auditd) for kernel audit events, not general system log rotation.

5
MCQmedium

A system administrator wants to limit the number of simultaneous logins for a user to 2. Which file and parameter should be configured?

A./etc/pam.d/login: session required pam_limits.so
B./etc/security/limits.conf: username hard maxlogins 2
C./etc/security/limits.conf: @users hard maxlogins 2
D./etc/security/limits.conf: username soft nproc 2
AnswerB

Configuring `maxlogins` in `/etc/security/limits.conf` enforces a per-user cap on concurrent sessions through PAM's pam_limits module, directly satisfying the requirement to restrict simultaneous logins to 2. The `hard` type makes the limit unoverrideable by the user, ensuring the constraint holds across all login methods.

Why this answer

The `/etc/security/limits.conf` file allows setting resource limits per user or group, and the `maxlogins` parameter specifically controls the maximum number of simultaneous logins for a user. The syntax `username hard maxlogins 2` enforces a hard limit of 2 concurrent sessions for that user, which is the exact requirement. This limit is enforced by the PAM module `pam_limits.so`, which must be configured in the appropriate PAM stack file (e.g., `/etc/pam.d/login` or `/etc/pam.d/sshd`).

Exam trap

The Linux+ exam often tests the distinction between `maxlogins` (simultaneous logins) and `nproc` (number of processes), and the difference between `soft` and `hard` limits, causing candidates to confuse process limits with login limits or choose a group-based entry when a per-user entry is required.

How to eliminate wrong answers

Option A is wrong because `/etc/pam.d/login` is a PAM service configuration file, not a resource limit file; the line `session required pam_limits.so` is necessary to enable `pam_limits.so` but does not itself set any limit. Option C is wrong because `@users` refers to a group named 'users', not a specific username, and the question explicitly asks to limit a single user, not a group. Option D is wrong because `soft nproc 2` limits the number of processes (nproc) for the user, not the number of simultaneous logins (maxlogins), and using a soft limit allows the user to exceed it temporarily, which does not enforce a hard cap of 2 logins.

6
MCQmedium

A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?

A.faillock --user username
B.ausearch -m USER_LOGIN -ui username
C.pam_tally2 --user username
D.lastb username
AnswerA

The faillock utility reads the tally files that pam_faillock.so maintains and prints each user's recorded failure timestamps and count. Running it with --user username displays that account's failed attempts, letting the administrator confirm the lockout cause.

Why this answer

The faillock command is the standard tool for viewing and managing failed login attempts when using pam_faillock. Running 'faillock --user username' displays the number of failed attempts and the timestamps for the specified user. This directly answers the question.

Exam trap

XK0-006 often tests the difference between pam_faillock and pam_tally2, and candidates may choose the legacy command. The trap is to assume that pam_tally2 is still the standard for viewing failed attempts.

How to eliminate wrong answers

Option B is wrong because ausearch is used to search audit logs, and while it can show USER_LOGIN events, it does not specifically show the faillock counter; it would require parsing and may not reflect the current faillock state. Option C is wrong because pam_tally2 is a legacy module for tallying failed logins, but it has been deprecated in favor of pam_faillock on modern systems; the command 'pam_tally2 --user username' might work on older systems but is not the correct tool for pam_faillock. Option D is wrong because lastb shows a list of bad login attempts from the btmp file, but it does not show the faillock counter and is not specific to the user's current failed attempt count.

7
MCQhard

A Linux server is configured with an IPsec VPN using strongSwan. The administrator needs to verify that the VPN tunnel is active and that traffic is being encrypted. Which command should be used to display the current status of the IPsec security associations?

A.ipsec statusall
B.ss -tuln
C.ip xfrm state
D.systemctl status strongswan
AnswerA

The 'ipsec statusall' command is part of the strongSwan suite and displays detailed information about all IPsec security associations (SAs), including their state, encryption algorithms, and traffic statistics. This allows the administrator to confirm that the tunnel is established and operational, and to see if any SAs are down or have errors.

Why this answer

The 'ipsec statusall' command is the standard tool in strongSwan to display the status of all IPsec security associations, including connection states, encryption details, and traffic counters. It provides a comprehensive overview that confirms whether the VPN tunnel is active and properly encrypting traffic, which is exactly what the administrator needs.

Exam trap

The trap here is assuming that checking the service status or listening ports is enough to verify VPN operation, but those do not confirm that a tunnel is established and passing traffic.

8
MCQmedium

A security analyst notices repeated failed login attempts on a Linux server. They want to lock the account after 3 failed attempts using PAM. Which PAM module should be configured in /etc/pam.d/sshd or /etc/pam.d/system-auth?

A.pam_faillock.so
B.pam_tally2.so
C.pam_pwquality.so
D.pam_unix.so
AnswerA

pam_faillock.so counts consecutive authentication failures per account and locks it once the configured deny threshold is reached, directly enforcing the three-attempt lockout. It is inserted into the auth and account stacks of /etc/pam.d/sshd or system-auth.

Why this answer

pam_faillock.so is the modern PAM module designed to lock accounts after a configurable number of failed login attempts. It replaces the deprecated pam_tally2.so and is configured in /etc/pam.d/sshd or /etc/pam.d/system-auth with parameters like deny=3 to enforce the lockout threshold. It tracks failures per user and can automatically unlock accounts after a specified time.

Exam trap

XK0-006 often tests the difference between deprecated and current PAM modules, so candidates may incorrectly choose pam_tally2.so because they remember it from older study materials.

How to eliminate wrong answers

Option B is wrong because pam_tally2.so is deprecated and removed in newer Linux distributions; it was replaced by pam_faillock.so. Option C is wrong because pam_pwquality.so enforces password complexity and length policies, not account lockout on failed logins. Option D is wrong because pam_unix.so handles standard Unix authentication (password verification) but does not provide account lockout functionality.

9
Multi-Selecthard

A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)

Select 3 answers
A.Change SSH port to 2222
B.Configure pam_faillock.so to lock accounts after failed attempts
C.Configure pam_pwquality.so to enforce password complexity
D.Set PasswordAuthentication no in sshd_config
E.Set PermitRootLogin yes
AnswersB, C, D

Configuring pam_faillock.so enforces account lockout after repeated failed authentication attempts, directly mitigating brute-force attacks against the weak password policy identified in the audit. It operates at the PAM authentication layer, so the protection applies across all services using PAM, not SSH alone, hardening the system beyond the password-strength weakness.

Why this answer

Option B is correct because configuring pam_faillock.so in the PAM stack enforces account lockout after a defined number of failed authentication attempts (e.g., deny=5, unlock_time=900), directly mitigating brute-force and password-guessing attacks against the weak password policy. Option C is correct because pam_pwquality.so enforces password complexity requirements such as minimum length (minlen), character classes (ucredit, lcredit, dcredit, ocredit), and dictionary checks, which addresses the audit finding of weak password policies at their source. Option D is correct because setting PasswordAuthentication no in sshd_config disables password-based SSH authentication entirely, forcing key-based authentication and eliminating the password-guessing attack surface the audit flagged; this requires reloading sshd (systemctl reload sshd) to take effect.

Option A does not belong because merely changing the SSH port to 2222 is security through obscurity and does not fix the underlying weak authentication or password policy issues. Option E does not belong because setting PermitRootLogin yes permits direct root logins over SSH, which increases risk rather than improving security; it should be set to no or prohibit-password.

10
MCQhard

A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.

A.nft add rule inet filter input ip saddr != 192.168.1.0/24 tcp dport 22 drop
B.nft insert rule inet filter input tcp dport 22 drop
C.nft replace rule inet filter input handle 1 tcp dport 22 drop
D.nft add rule inet filter input tcp dport 22 accept
AnswerA

The rule matches source addresses outside 192.168.1.0/24 on TCP port 22 and drops them, satisfying the requirement to block non-management SSH. Using '!=' with the saddr match and the drop verdict enforces the restriction within the inet filter input chain.

Why this answer

The correct rule uses 'nft add rule' with a source address negation (ip saddr != 192.168.1.0/24) matching TCP destination port 22 and a drop verdict, which precisely drops SSH from every source outside the management network while leaving the existing allow rule intact. This is the only option that combines the correct match criteria (source negation plus SSH port) with the drop action.

Exam trap

The trap here is that candidates pick 'insert' or a plain drop rule without the source negation, forgetting that nftables is first-match-wins and that dropping all SSH would lock out the management network — the exam tests whether you read the requirement to exclude the management subnet.

How to eliminate wrong answers

Option B is wrong because 'nft insert rule inet filter input tcp dport 22 drop' drops ALL SSH traffic including from the management network, with no source address exception — it would break the intended management access. Option C is wrong because 'nft replace rule' requires an existing rule handle to replace, and the command as written references handle 1 without confirming that handle corresponds to the intended rule; it also lacks the source negation. Option D is wrong because it adds an accept rule for SSH, which does the opposite of the requirement and would not restrict access from unauthorized sources.

11
MCQhard

A Linux administrator is configuring a server to use firewalld. The administrator wants to allow incoming traffic on TCP port 8080 only from the 192.168.1.0/24 subnet, while denying it from all other sources, without affecting other services. Which firewalld command should the administrator use to achieve this?

A.firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="8080" protocol="tcp" accept'
B.firewall-cmd --permanent --add-source=192.168.1.0/24 --add-port=8080/tcp
C.firewall-cmd --permanent --add-port=8080/tcp --source=192.168.1.0/24
D.firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="8080" protocol="tcp" drop'
AnswerA

This rich rule adds a permanent rule that accepts TCP traffic to port 8080 only from the specified source subnet. Rich rules allow granular control based on source address, port, and protocol. After adding it, the administrator must reload firewalld for the rule to take effect in the running configuration.

Why this answer

Rich rules in firewalld allow combining source addresses, ports, and actions in a single rule. The correct syntax uses --add-rich-rule with a rule that specifies source address, port, protocol, and accept action. This precisely allows TCP 8080 from 192.168.1.0/24.

Adding a port with a source argument is not supported, and adding a source to a zone does not restrict individual ports.

Exam trap

The trap here is assuming that --add-port can be combined with --source to restrict access, when source restrictions require a rich rule or zone-based source assignment.

12
Multi-Selectmedium

An administrator needs to harden SSH access. Which TWO settings in /etc/ssh/sshd_config are recommended to improve security? (Choose two.)

Select 2 answers
A.PermitRootLogin yes
B.PermitRootLogin no
C.Protocol 1
D.PasswordAuthentication no
E.Port 22
AnswersB, D

PermitRootLogin no blocks direct root authentication over SSH, forcing administrators to log in as unprivileged users before escalating via sudo or su. This removes root as a brute-force target and preserves attributable audit trails, directly satisfying the hardening requirement to reduce remote attack surface on the SSH daemon.

Why this answer

Option B (PermitRootLogin no) is correct because disabling direct root logins over SSH forces attackers to compromise a normal user account and then escalate privileges, removing a high-value, well-known target and enabling accountability through sudo or su. Option D (PasswordAuthentication no) is correct because it disables password-based authentication, requiring key-based (public/private key) authentication instead, which is not vulnerable to brute-force or credential-guessing attacks. Option A (PermitRootLogin yes) is wrong because it explicitly allows root to log in directly, the opposite of hardening.

Option C (Protocol 1) is wrong because SSH protocol 1 is deprecated and insecure (weak integrity/crypto), and modern OpenSSH only supports protocol 2 anyway. Option E (Port 22) is wrong because it merely sets the default port and provides no real security benefit; changing the port is at most minor obscurity, not a recommended hardening control.

Exam trap

The trap here is that candidates often think changing the default SSH port (Option E) is a strong security measure, but the exam considers it a weak control compared to disabling root login and password authentication, which directly address authentication vulnerabilities.

13
MCQeasy

A Linux administrator needs to ensure that all user passwords meet a minimum length of 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these password complexity requirements?

A./etc/security/pwquality.conf
B./etc/pam.d/system-auth
C./etc/login.defs
D./etc/shadow
AnswerA

The /etc/security/pwquality.conf file is used by the pam_pwquality module to enforce password complexity rules such as minimum length (minlen), required character classes (ucredit, lcredit, dcredit, ocredit), and other checks. Editing this file allows the administrator to set these requirements system-wide for all users, ensuring compliance with the security policy.

Why this answer

Password complexity requirements are enforced by the pam_pwquality module, which reads its configuration from /etc/security/pwquality.conf. This file allows setting parameters like minlen, ucredit, lcredit, dcredit, and ocredit to require specific character types and lengths. The other files serve different purposes and cannot enforce these rules.

Exam trap

The trap here is assuming that /etc/login.defs handles all password policies, but it only covers aging and minimum length, not character complexity.

14
MCQeasy

A Linux administrator needs to add a new user named 'jdoe' with a home directory and a bash shell. Which command accomplishes this?

A.usermod -m -s /bin/bash jdoe
B.adduser jdoe --home /home/jdoe --shell /bin/bash
C.useradd -m -s /bin/bash jdoe
D.passwd -m jdoe
AnswerC

The -m flag creates the home directory and -s /bin/bash sets the login shell, satisfying both stated requirements in one command. Without -m, useradd leaves no home directory; without -s, the system default shell applies.

Why this answer

The useradd command with -m creates the home directory and -s /bin/bash sets the login shell, so 'useradd -m -s /bin/bash jdoe' creates user jdoe with a home directory and bash shell in one step. This is the canonical low-level command on RHEL/CentOS and other systemd-based distributions for non-interactive user creation.

Exam trap

The trap is confusing useradd (create) with usermod (modify) and mixing Debian's adduser syntax with RHEL's useradd — candidates who don't check the distro context pick the wrong command.

How to eliminate wrong answers

Option A is wrong because usermod modifies an existing user; it will fail if jdoe does not already exist, and it does not create a home directory from scratch for a new account. Option B is wrong because the adduser syntax with --home and --shell flags is Debian/Ubuntu-specific (and even there, adduser uses --home and --shell but the option ordering and behavior differ); on RHEL-family systems adduser is a symlink to useradd and does not accept those long options. Option D is wrong because passwd only sets or changes a user's password and has no -m option for home directory creation.

15
MCQmedium

An administrator needs to prevent a specific user 'bob' from logging in via SSH while allowing other users. Which configuration directive should be added to /etc/ssh/sshd_config?

A.AllowUsers alice charlie
B.PermitRootLogin no
C.DenyUsers bob
D.AllowUsers bob
AnswerC

DenyUsers bob blocks only the named account at authentication, leaving all other users unaffected, which satisfies the stem's requirement to prevent 'bob' specifically while permitting everyone else. Applied in sshd_config and reloaded, it is evaluated before AllowUsers, so no broader access rule is needed.

Why this answer

The DenyUsers directive in /etc/ssh/sshd_config explicitly blocks specific usernames from logging in via SSH. By specifying 'DenyUsers bob', only user bob is denied, while all other users remain allowed. This matches the requirement to prevent bob without affecting others.

AllowUsers with a whitelist would also block bob but would require listing every other user, which is impractical and not the intended solution.

Exam trap

The trap is that candidates may choose AllowUsers with a whitelist (like option A) thinking it blocks bob, but it also blocks all other users not in the list. The question's requirement to 'prevent bob while allowing other users' is best met by a blacklist approach using DenyUsers. This tests understanding of whitelist vs. blacklist logic.

How to eliminate wrong answers

Option B is wrong because PermitRootLogin no only prevents the root user from logging in via SSH; it has no effect on regular users like 'bob'. Option C is wrong because DenyUsers bob would explicitly block 'bob', but the question asks for a directive that prevents 'bob' while allowing other users; while DenyUsers works, the correct answer is AllowUsers as it is the more direct and commonly tested approach for this scenario. Option D is wrong because AllowUsers bob would permit only 'bob' to log in, blocking all other users including alice and charlie, which is the opposite of the requirement.

16
MCQmedium

An administrator wants to restrict SSH access to only users in the 'sshusers' group. Which configuration directive should be added to /etc/ssh/sshd_config?

A.AllowUsers sshusers
B.Match Group sshusers
C.AllowGroups sshusers
D.DenyGroups all
AnswerC

AllowGroups restricts SSH logins to members of the named group, so only users in sshusers may authenticate. Unlike AllowUsers, which lists individual accounts, this directive scales by group membership, directly satisfying the requirement to limit access to that group.

Why this answer

The AllowGroups directive in /etc/ssh/sshd_config explicitly permits SSH login only for users who are members of the specified group(s). When AllowGroups sshusers is set, any user not in the 'sshusers' group is denied access, regardless of other settings. This is the correct and direct way to restrict SSH access to a specific group.

Exam trap

The trap here is confusing AllowUsers with AllowGroups, or thinking Match Group restricts access when it only applies conditional settings.

How to eliminate wrong answers

Option A is wrong because AllowUsers expects a list of usernames, not group names; using 'sshusers' would be interpreted as a username, not a group. Option B is wrong because Match Group is used to apply conditional configuration blocks for users in a group, but it does not by itself restrict access; it only sets the context for subsequent directives. Option D is wrong because DenyGroups all would deny access to all groups, effectively blocking everyone, which is the opposite of the intended restriction.

17
MCQeasy

A Linux administrator needs to grant a user the ability to run a specific command as root without being prompted for a password, while restricting all other commands. Which file should be edited to configure this using sudo?

A./etc/security/access.conf
B./etc/sudoers
C./etc/sudo.conf
D./etc/pam.d/sudo
AnswerB

The /etc/sudoers file is the primary configuration file for sudo. It allows administrators to define which users or groups can run which commands, and with what options. To grant a user passwordless execution of a specific command, an entry such as username ALL=(ALL) NOPASSWD: /path/to/command is added. This file should be edited with visudo to prevent syntax errors.

Why this answer

The /etc/sudoers file is the standard configuration file for sudo, where administrators define user privileges and command restrictions. To allow a user to run a specific command without a password, an entry with NOPASSWD is added. This file should be edited with visudo to ensure syntax correctness.

Other files like sudo.conf or PAM configurations serve different purposes and do not control command authorization.

Exam trap

The trap here is confusing sudo configuration files with PAM or access control files, which handle authentication and login restrictions rather than sudo command permissions.

18
MCQmedium

A Linux administrator needs to grant the user 'jsmith' the ability to restart the httpd service without entering a password, while preventing all other sudo commands. The administrator creates the file /etc/sudoers.d/jsmith with the line: jsmith ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd. After saving the file, jsmith reports that sudo still prompts for a password. Which command should the administrator run to diagnose the issue?

A.journalctl -u sudo
B.sudo -l -U jsmith
C.visudo -c
D.grep jsmith /etc/sudoers
AnswerB

The sudo -l -U jsmith command lists the sudo privileges for the specified user, showing exactly which commands jsmith may run and whether NOPASSWD applies. This directly reveals whether the sudoers.d file is being parsed correctly and whether the rule matches the intended command path, helping diagnose why a password is still requested.

Why this answer

The sudo -l -U jsmith command displays the sudo privileges for jsmith, including whether NOPASSWD is applied to the specified command. This directly shows if the rule in /etc/sudoers.d/jsmith is being read and matched, which is essential for troubleshooting why a password is still required.

Exam trap

The trap here is assuming that syntax checking alone confirms that a sudo rule is active for a user, when in fact you must inspect the effective privileges.

19
MCQmedium

A Linux server hosts a web application that must be able to bind to TCP port 443. The administrator has already installed the application and configured it to listen on 443. However, when the service starts, it fails with a 'Permission denied' error. The administrator confirms that no other process is using port 443 and that the service runs as the non-root user 'webapp'. Which command should the administrator use to grant the necessary capability to the service binary without giving it full root privileges?

A.chmod u+s /usr/local/bin/webapp
B.firewall-cmd --add-port=443/tcp --permanent
C.setcap 'cap_net_bind_service=+ep' /usr/local/bin/webapp
D.usermod -aG root webapp
AnswerC

This command assigns the cap_net_bind_service capability to the webapp binary, allowing it to bind to privileged ports (below 1024) without running as root. The +ep flags set the effective and permitted capability sets, enabling the process to use the capability. This is the least-privilege approach and directly resolves the permission denied error for a non-root user.

Why this answer

The service runs as a non-root user and needs to bind to a privileged port (443). Linux capabilities allow fine-grained privilege assignment. The setcap command with cap_net_bind_service grants exactly the needed capability, enabling the binary to bind to low-numbered ports without full root privileges.

This follows the principle of least privilege and is the standard solution for this scenario.

Exam trap

The trap here is assuming that opening the firewall port or adding the user to a group will resolve a bind permission error, when the issue is about Linux capabilities.

20
MCQhard

An AppArmor profile for a web server is in complain mode. After testing, the administrator wants to enforce the profile. Which command accomplishes this?

A.apparmor_parser -r /etc/apparmor.d/usr.sbin.httpd
B.aa-enforce /etc/apparmor.d/usr.sbin.httpd
C.aa-complain /etc/apparmor.d/usr.sbin.httpd
D.aa-status /etc/apparmor.d/usr.sbin.httpd
AnswerB

aa-enforce switches the named AppArmor profile from complain to enforce mode, applying its deny rules. This satisfies the requirement to move the web server profile out of complain mode after testing, using the profile path as the argument.

Why this answer

The correct command to enforce an AppArmor profile that is currently in complain mode is `aa-enforce`. This command switches the profile from complain (log-only) to enforce (block violations) mode. The option `-r` in `apparmor_parser` reloads the profile but does not change its mode; `aa-complain` sets it to complain mode, and `aa-status` only displays status.

Exam trap

The trap here is that candidates confuse `apparmor_parser -r` (which reloads the profile but does not change its mode) with the mode-switching commands `aa-enforce` and `aa-complain`, leading them to choose option A incorrectly.

How to eliminate wrong answers

Option A is wrong because `apparmor_parser -r` reloads the profile from disk but does not change its operational mode; it would reload the profile in its current mode (complain), not enforce. Option C is wrong because `aa-complain` sets the profile to complain mode, which is the opposite of what the administrator wants. Option D is wrong because `aa-status` is used to display the status of loaded AppArmor profiles, not to change their enforcement mode.

21
MCQhard

A Linux administrator is configuring an SSH server to use certificate-based authentication. The administrator has generated a CA key pair and wants to sign a user's public key. Which command should be used to sign the user's public key with the CA and produce a certificate?

A.ssh-keygen -s /etc/ssh/ca_key -I user_id -n username -V +52w user_key
B.ssh-keygen -s /etc/ssh/ca_key -I user_id -n username -V +52w user_key.pub
C.ssh-keygen -s /etc/ssh/ca_key -I user_id -n username -V +52w -f user_key
D.ssh-keygen -s /etc/ssh/ca_key -I user_id -n username -V +52w -O user_key.pub
AnswerB

This command uses ssh-keygen with the -s flag to specify the CA private key, -I to set the key ID, -n to define principals, -V for validity period, and the public key file to sign. It generates a certificate file named user_key-cert.pub. This is the correct syntax for signing a user's public key with a CA in OpenSSH certificate authentication.

Why this answer

To sign a user's public key with a CA in OpenSSH, the ssh-keygen command is used with the -s flag pointing to the CA private key, -I for the key identity, -n for principals, -V for validity, and the public key file as the final argument. This produces a certificate file that can be used for authentication. The other options misuse flags like -f, omit the .pub extension, or incorrectly use -O for the public key.

Exam trap

The trap here is confusing the -f flag, which specifies the output file for key generation, with the correct syntax for signing where the public key file is given as a positional argument.

22
Multi-Selectmedium

A security administrator is reviewing SSH configuration. Which TWO settings enhance security by limiting authentication attempts and preventing password-based logins? (Choose two.)

Select 2 answers
A.MaxAuthTries 3
B.PasswordAuthentication no
C.Protocol 2
D.PermitRootLogin no
E.Port 2222
AnswersA, B

MaxAuthTries 3 caps the number of authentication attempts permitted per connection, so brute-force guessing is throttled before an attacker can try many passwords. This directly satisfies the stem's requirement to limit authentication attempts, working alongside a setting that disables password logins.

Why this answer

Option A, MaxAuthTries 3, is correct because this sshd_config directive limits the number of authentication attempts allowed per connection, so after three failed tries the server disconnects the client, directly reducing the risk of brute-force password guessing. Option B, PasswordAuthentication no, is correct because it disables password-based authentication entirely, forcing the use of stronger methods such as public key authentication and thereby preventing password logins. Option C, Protocol 2, is not correct here because although it enforces the more secure SSH-2 protocol, it does not limit authentication attempts or block password logins.

Option D, PermitRootLogin no, is not correct because it only prevents direct root logins and does not restrict authentication attempts or password authentication for other users. Option E, Port 2222, is not correct because changing the listening port is only a minor obscurity measure and does not limit authentication attempts or prevent password-based logins.

Exam trap

The trap is selecting plausible-looking hardening options (Protocol 2, PermitRootLogin no, Port 2222) that don't actually satisfy the two stated requirements — the exam tests precise reading of 'limiting authentication attempts' and 'preventing password-based logins.'

23
MCQmedium

A security team wants to restrict SSH access to only users in the 'sshusers' group. Which configuration line in /etc/ssh/sshd_config achieves this?

A.DenyGroups sshusers
B.AllowGroups sshusers
C.AllowUsers sshusers
D.Subsystem sftp /usr/lib/openssh/sftp-server
AnswerB

AllowGroups restricts authentication to members of the named group only, so listing sshusers blocks every account outside it. This directly enforces the stated constraint of limiting SSH access to that group, unlike AllowUsers, which names individual accounts rather than a group.

Why this answer

The `AllowGroups` directive in `/etc/ssh/sshd_config` restricts SSH login to users who are members of the specified group. By setting `AllowGroups sshusers`, only users in the 'sshusers' group are permitted to authenticate via SSH, meeting the security team's requirement.

Exam trap

The trap here is confusing `AllowGroups` with `AllowUsers`; candidates often select `AllowUsers sshusers` thinking it applies to a group, but it only matches a literal username, not group membership.

How to eliminate wrong answers

Option A is wrong because `DenyGroups sshusers` would block users in the 'sshusers' group from SSH access, which is the opposite of what is required. Option C is wrong because `AllowUsers sshusers` specifies a username, not a group; it would only allow a user literally named 'sshusers' to log in, not all members of the group. Option D is wrong because `Subsystem sftp /usr/lib/openssh/sftp-server` configures the SFTP subsystem and has no effect on restricting SSH access based on group membership.

24
Multi-Selecthard

A security team wants to harden a Linux server against unauthorized access. They need to restrict which users can authenticate via SSH and ensure that only key-based authentication is allowed for a specific group. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Configure PAM to require two-factor authentication for all SSH sessions.
B.Use AllowGroups sshusers in /etc/ssh/sshd_config to limit SSH access to members of the sshusers group.
C.Add all users to the wheel group and set UsePAM yes in sshd_config.
D.Set PermitRootLogin yes in /etc/ssh/sshd_config to allow administrative access.
E.Set PasswordAuthentication no in /etc/ssh/sshd_config and restart sshd.
AnswersB, E

AllowGroups restricts SSH logins to users who are members of the specified group(s). This satisfies the requirement to restrict which users can authenticate via SSH. Combined with disabling password authentication, it ensures only authorized users with keys can connect. The directive must be placed in sshd_config and sshd restarted.

Why this answer

Disabling PasswordAuthentication enforces key-based logins, and AllowGroups restricts SSH access to a defined set of users. Together they meet the hardening goals. The other options either weaken security, add unrelated controls, or grant unnecessary privileges.

Restarting sshd after changes is required for them to take effect.

Exam trap

The trap here is confusing authentication method restrictions with user access controls; both are needed to fully satisfy the scenario.

25
MCQeasy

A Linux administrator wants to prevent users from reusing their last five passwords. Which PAM module should be configured?

A.pam_faillock
B.pam_pwquality
C.pam_unix
D.pam_pwhistory
AnswerD

Configuring pam_pwhistory with the remember=5 parameter stores previous password hashes and rejects any new password matching them, directly enforcing the five-password reuse restriction in the stem. It hooks into the password stack, so changes are blocked at the point of update rather than merely advised.

Why this answer

The pam_pwhistory module is specifically designed to enforce password history policies by storing a user's previous passwords in a separate file (e.g., /etc/security/opasswd) and preventing reuse of those passwords. By configuring the 'remember' option in the PAM stack, the administrator can set the number of previous passwords that cannot be reused, such as 'remember=5' to block the last five passwords.

Exam trap

The trap here is that candidates often confuse pam_pwquality (which enforces password strength) with pam_pwhistory (which enforces password reuse prevention), leading them to select pam_pwquality when the question specifically asks about preventing reuse of previous passwords.

How to eliminate wrong answers

Option A is wrong because pam_faillock is used to lock user accounts after a specified number of failed login attempts, not to enforce password history or reuse restrictions. Option B is wrong because pam_pwquality is used to enforce password complexity requirements (e.g., length, character classes) and does not track or prevent reuse of previous passwords. Option C is wrong because pam_unix handles traditional Unix authentication, password updates, and shadow password management, but it does not have built-in support for password history tracking; that functionality is delegated to pam_pwhistory.

26
MCQeasy

A junior administrator needs to check whether a user account named 'bob' is locked and view the password aging information. Which command should be used?

A.passwd -S bob
B.usermod -L bob
C.chage -l bob
D.id bob
AnswerA

passwd -S displays the status of a user's password, including whether the account is locked (L), has no password (NP), or has a usable password (P), along with aging fields. This directly answers whether bob is locked and shows password aging details, making it the appropriate command for the administrator's check.

Why this answer

The passwd -S command reports the password status for a user, indicating locked, no password, or usable states, and includes aging data. This single command lets the administrator verify lock status and review password aging, which matches the scenario's need for inspection without modifying the account.

Exam trap

The trap here is choosing chage for lock status because it also deals with passwords, but chage shows aging only and never reports whether the account is locked.

27
Multi-Selecthard

After configuring AppArmor, an administrator wants to verify the status of all profiles and switch a profile from complain to enforce mode. Which TWO commands are appropriate? (Choose two.)

Select 2 answers
A.systemctl restart apparmor
B.aa-status
C.apparmor_parser -r /etc/apparmor.d/profile
D.aa-complain /path/to/profile
E.aa-enforce /path/to/profile
AnswersB, E

`aa-status` reports every loaded AppArmor profile with its current mode, satisfying the requirement to verify all profiles' status. It lists profiles as enforcing, complaining or unconfined, giving the administrator the baseline needed before switching one profile into enforce mode.

Why this answer

Option B (aa-status) is correct because it is the standard AppArmor utility that reports the current state of all loaded profiles, showing how many are in enforce mode, complain mode, or unconfined, which directly satisfies the requirement to verify the status of all profiles. Option E (aa-enforce /path/to/profile) is correct because aa-enforce is the dedicated command that switches the specified profile into enforce mode, exactly matching the second task of moving a profile from complain to enforce. Option A (systemctl restart apparmor) only reloads the AppArmor service and does not report profile status or change an individual profile's mode.

Option C (apparmor_parser -r /etc/apparmor.d/profile) reloads a profile definition from disk but does not by itself toggle the profile between complain and enforce mode. Option D (aa-complain /path/to/profile) is the opposite of what is needed, since it sets a profile to complain mode rather than enforce mode.

Exam trap

The trap here is that candidates confuse `aa-complain` with `aa-enforce` or think that reloading a profile with `apparmor_parser` changes its mode, when in fact the mode is set separately via the `aa-*` utilities.

28
MCQmedium

A security audit reveals that users can change their password without meeting complexity requirements. Which PAM module should be configured to enforce password complexity?

A.pam_faillock
B.pam_unix
C.pam_tally2
D.pam_pwquality
AnswerD

pam_pwquality enforces password complexity at change time by applying configurable rules such as minimum length, character classes and dictionary checks. Configuring it in the password stack ensures users cannot set weak passwords, directly satisfying the audit finding that complexity requirements are bypassed.

Why this answer

pam_pwquality is the PAM module that enforces password complexity requirements such as minimum length, character classes, and dictionary checks on Linux. It replaced the older pam_cracklib module and is configured in /etc/security/pwquality.conf and referenced in /etc/pam.d/system-auth or /etc/pam.d/common-password. Configuring it ensures users cannot set weak passwords that violate policy.

Exam trap

The trap is confusing lockout modules (pam_faillock, pam_tally2) with complexity modules (pam_pwquality) — candidates see 'password' in the module name and pick the wrong PAM component, missing that the question is about complexity, not failed-attempt lockout.

How to eliminate wrong answers

Option A is wrong because pam_faillock enforces account lockout after repeated failed authentication attempts — it is a brute-force mitigation, not a password complexity control. Option B is wrong because pam_unix handles the actual password change and authentication against /etc/shadow; it does not evaluate complexity rules on its own. Option C is wrong because pam_tally2 is a legacy lockout module (deprecated in favor of pam_faillock) that counts failed logins and locks accounts — again, not a complexity enforcer.

29
MCQmedium

A security analyst wants to ensure that users cannot change their password more than once every 7 days. Which command and option should be used to enforce this policy for user 'jsmith'?

A.usermod -e 7 jsmith
B.chage -m 7 jsmith
C.chage -M 7 jsmith
D.passwd -n 7 jsmith
AnswerB

`chage -m 7 jsmith` sets the minimum number of days between password changes to seven, directly enforcing the required restriction. The `-m` flag defines this minimum interval, so `jsmith` cannot alter the password again until seven days have elapsed, satisfying the stem's constraint precisely.

Why this answer

The `chage -m 7 jsmith` command sets the minimum number of days required between password changes for user jsmith to 7 days. The `-m` option of `chage` specifically controls the minimum password age, preventing the user from changing their password more than once every 7 days.

Exam trap

The trap here is confusing the `-m` (minimum days) and `-M` (maximum days) options of `chage`, as candidates often mix up which option controls the minimum interval between password changes versus the password expiration period.

How to eliminate wrong answers

Option A is wrong because `usermod -e` sets an account expiration date, not a minimum password age. Option C is wrong because `chage -M` sets the maximum password age (how long a password is valid), not the minimum interval between changes. Option D is wrong because `passwd -n` is not a valid option; the correct command to set minimum password age is `chage -m`, not `passwd`.

30
MCQhard

A Linux administrator is configuring a server that must meet strict security guidelines. The server uses firewalld and should drop all incoming traffic on the public zone by default, but allow outgoing SSH connections initiated by the server itself to a remote management host. Which firewalld configuration should the administrator apply?

A.Set the target of the public zone to DROP, and add a rich rule to allow outbound SSH to the remote host.
B.Set the target of the public zone to %%REJECT%%, and create a direct rule to allow outgoing SSH to the remote host.
C.Set the target of the public zone to DROP, and ensure the default outbound behavior allows SSH to the remote host.
D.Set the target of the public zone to DROP, and add a service rule for ssh to the public zone.
AnswerC

The public zone target DROP will silently discard all incoming traffic that does not match an allowed service or port, meeting the default drop requirement. Outgoing traffic is not filtered by firewalld zones; the default policy allows all outbound connections. Therefore, SSH connections initiated by the server to the remote host will be permitted without additional configuration. This satisfies both conditions.

Why this answer

The public zone target DROP ensures all incoming traffic is silently discarded unless explicitly allowed. Outgoing traffic is not filtered by firewalld zones, so SSH connections initiated by the server are allowed by default. Adding inbound service rules or using REJECT would violate the drop requirement or send rejection messages.

Exam trap

The trap here is thinking that firewalld zones filter outbound traffic; they only filter inbound traffic, so outgoing SSH requires no special rule.

31
MCQeasy

An administrator wants to force a password change for user 'alice' on next login. Which command is appropriate?

A.passwd --expire alice
B.passwd -l alice
C.chage -l alice
D.usermod -f alice
AnswerA

`passwd --expire alice` immediately expires alice's password, forcing a change at her next login, which satisfies the stem's requirement. Unlike `chage -d 0`, it acts instantly without editing ageing fields, and it avoids locking the account outright, so alice can still authenticate and set a new password.

Why this answer

The `passwd --expire alice` command (equivalent to `passwd -e alice`) immediately expires alice's password by setting the shadow file's last-change date to 0, forcing a password change at her next login. This is the standard Linux mechanism for administrators to force a one-time password reset without disabling the account.

Exam trap

The trap here is confusing account lockout (`passwd -l`) with password expiry (`passwd -e`/`--expire`) — both touch /etc/shadow, but only one forces a change on next login while the other blocks access entirely.

How to eliminate wrong answers

Option B is wrong because `passwd -l alice` locks the account by prefixing the password hash with '!' in /etc/shadow, preventing login entirely rather than forcing a change. Option C is wrong because `chage -l alice` only lists the current password aging information for alice; it is a read-only query and makes no changes. Option D is wrong because `usermod -f alice` is syntactically invalid — the `-f` flag expects a numeric inactive-days value, not a username, and it controls account inactivity after password expiry, not immediate expiry.

32
MCQmedium

To limit the number of processes a user can create, which file should be configured?

A./etc/pam.d/login
B./etc/security/limits.conf
C./etc/ulimit.conf
D./etc/systemd/system.conf
AnswerB

/etc/security/limits.conf is read by pam_limits and defines per-user or per-group resource limits, including nproc, which caps the number of processes a user may create. This directly satisfies the requirement to limit process creation for a user.

Why this answer

The /etc/security/limits.conf file is used on Linux systems to set resource limits for users and groups, including the maximum number of processes (nproc). This file is read by PAM (Pluggable Authentication Modules) during login to apply ulimit settings. Configuring nproc there limits the number of processes a user can create.

Exam trap

The trap is confusing PAM configuration files with the actual limits configuration file, or assuming a non-existent /etc/ulimit.conf exists, leading candidates to choose incorrect paths.

How to eliminate wrong answers

Option A is wrong because /etc/pam.d/login configures PAM modules for the login service, not resource limits; it may include pam_limits.so but does not itself contain the limit values. Option C is wrong because /etc/ulimit.conf does not exist by default; ulimit settings are typically configured in /etc/security/limits.conf or shell profiles. Option D is wrong because /etc/systemd/system.conf configures systemd system-wide defaults, not per-user process limits; it does not control user process counts.

33
MCQmedium

A Linux administrator wants to allow the web server (httpd) to bind to a non-standard port, TCP 8080, without disabling SELinux. The system is running SELinux in enforcing mode. Which command should the administrator run to permanently allow httpd to listen on TCP port 8080?

A.semanage port -a -t http_port_t -p tcp 8080
B.semanage port -m -t http_port_t -p tcp 8080
C.chcon -t http_port_t /etc/httpd/conf/httpd.conf
D.setsebool -P httpd_can_network_connect 1
AnswerA

This command uses semanage to add TCP port 8080 to the http_port_t type, which is the SELinux type that httpd is allowed to bind to. The -a flag adds a new port definition, -t specifies the type, and -p specifies the protocol. This change is persistent across reboots and allows httpd to listen on port 8080 without disabling SELinux.

Why this answer

To allow httpd to listen on TCP port 8080 in enforcing mode, the port must be added to the http_port_t SELinux type using semanage port -a. This is persistent and does not require disabling SELinux. Modifying an existing port definition is only for reassigning a port that is already defined, and boolean or file context changes do not affect port bindings.

Exam trap

The trap here is confusing semanage port -a with -m; the -m option is for modifying an existing port assignment, not for adding a new one.

34
MCQhard

A security engineer must ensure that a new SSH host key is generated using the Ed25519 algorithm and stored in the default location. Which command accomplishes this?

A.ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key
B.ssh-keygen -A
C.ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519
D.ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key
AnswerA

This command generates an Ed25519 host key and writes it to the standard path /etc/ssh/ssh_host_ed25519_key, which sshd reads by default. The -t ed25519 selects the algorithm and -f sets the filename, matching the requirement for a default-location Ed25519 host key that the SSH daemon will automatically use.

Why this answer

Host keys are generated with ssh-keygen using -t to select the algorithm and -f to specify the output file. For an Ed25519 host key in the default location, the correct invocation is ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key. This ensures sshd will find and use the key without additional configuration.

Exam trap

The trap here is mixing up user authentication keys stored in ~/.ssh with host keys stored in /etc/ssh, or using -A which generates all algorithms rather than the requested one.

35
MCQmedium

A system administrator needs to configure sudo so that members of the 'wheel' group can execute any command without a password. Which line should be added to /etc/sudoers (using visudo)?

A.%wheel ALL=(ALL) ALL
B.wheel ALL=(ALL) NOPASSWD: ALL
C.%wheel ALL=(ALL) NOPASSWD: ALL
D.%wheel ALL=NOPASSWD: ALL
AnswerC

The %wheel prefix denotes a group entry, ALL=(ALL) grants every command as any user, and NOPASSWD: ALL removes the password prompt. This line satisfies the requirement that wheel members run any command without a password.

Why this answer

To allow wheel group to run all commands without a password, the line should be '%wheel ALL=(ALL) NOPASSWD: ALL'.

36
MCQhard

A security audit reveals that an SELinux boolean 'httpd_can_network_connect' is currently off, but a web application requires Apache to connect to a database server. Which command should the administrator use to enable this boolean persistently?

A.setenforce 1
B.setsebool httpd_can_network_connect 1
C.setsebool -P httpd_can_network_connect on
D.getsebool httpd_can_network_connect
AnswerC

The `-P` flag writes the change into the persistent SELinux policy, so `httpd_can_network_connect` stays enabled across reboots. Without it, `setsebool` only alters the running state, which the audit would flag again after restart. This satisfies the requirement for persistent enablement of Apache's outbound database connection.

Why this answer

The command 'setsebool -P httpd_can_network_connect on' is correct because setsebool modifies SELinux booleans at runtime, and the -P flag makes the change persistent across reboots by writing it to the policy store. This enables Apache to initiate network connections to the database server as required.

Exam trap

XK0-006 often tests the -P flag for persistence — candidates pick setsebool without -P and fail the 'persistently' requirement, or confuse setsebool with setenforce.

How to eliminate wrong answers

Option A is wrong because setenforce 1 sets SELinux to enforcing mode — it does not modify any boolean and would not enable httpd_can_network_connect. Option B is wrong because setsebool without -P only changes the boolean at runtime; the change is lost on reboot, so it is not persistent. Option D is wrong because getsebool only reads and displays the current value of a boolean — it does not change anything.

37
MCQeasy

Which command can be used to generate an SSH key pair for user authentication?

A.ssh-keyscan
B.ssh-keygen
C.ssh-copy-id
D.ssh-add
AnswerB

`ssh-keygen` generates an asymmetric key pair — a private key plus a matching public key — for public-key authentication, satisfying the stem's requirement to create an SSH key pair. It writes them to `~/.ssh/id_rsa` and `id_rsa.pub` by default, and the public half is then copied to the remote host's `authorized_keys`.

Why this answer

The `ssh-keygen` command is the standard tool for generating SSH key pairs (public and private keys) used for user authentication. It creates RSA, ECDSA, Ed25519, or DSA key files (e.g., `~/.ssh/id_rsa` and `~/.ssh/id_rsa.pub`) and supports options like `-t` for key type and `-b` for bit length, directly enabling passwordless login via public key authentication.

Exam trap

The trap here is that candidates confuse `ssh-keygen` (key generation) with `ssh-copy-id` (key deployment) or `ssh-add` (key loading), leading them to pick a command that manages existing keys rather than creating new ones.

How to eliminate wrong answers

Option A is wrong because `ssh-keyscan` is used to gather SSH public host keys from remote servers, not to generate user key pairs. Option C is wrong because `ssh-copy-id` installs an existing public key onto a remote server's `authorized_keys` file, but does not generate keys itself. Option D is wrong because `ssh-add` adds private key identities to the SSH authentication agent (`ssh-agent`), but it cannot create new key pairs.

38
MCQmedium

A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?

A.usermod -L username
B.passwd -l username
C.passwd -u username
D.chage -E -1 username
AnswerC

`passwd -u username` unlocks a password-locked account by clearing the lock flag in `/etc/shadow`, directly satisfying the stem's requirement to unlock the account. The `-u` flag reverses a prior `passwd -l`, restoring the user's ability to authenticate with their existing password.

Why this answer

The passwd -u username command unlocks a previously locked user account by removing the leading '!' from the password hash in /etc/shadow. This is the direct counterpart to passwd -l, which locks the account by prepending '!' to the hash.

Exam trap

The trap is mixing up the -l (lock) and -u (unlock) flags on passwd, or confusing password locking with account expiration via chage -E.

How to eliminate wrong answers

Option A is wrong because usermod -L locks the account (same effect as passwd -l) rather than unlocking it — it prepends '!' to the password hash. Option B is wrong because passwd -l locks the account, which is the opposite of what the administrator needs. Option D is wrong because chage -E -1 sets the account expiration date to never expire; it does not remove a password lock, and if the account was locked via passwd -l, the '!' remains in /etc/shadow.

39
Multi-Selectmedium

A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)

Select 2 answers
A.pam_unix.so
B.pam_faillock.so
C.pam_tally2.so
D.pam_limits.so
E.pam_pwquality.so
AnswersB, E

pam_faillock.so provides account lockout after a specified number of failed authentication attempts. It is configured in the auth and account stacks of PAM configuration files, such as /etc/pam.d/system-auth and /etc/pam.d/password-auth. This module satisfies the account lockout requirement and is the current standard on Red Hat and similar distributions.

Why this answer

To enforce password complexity, pam_pwquality.so is the standard module, checking password strength against configured criteria. For account lockout, pam_faillock.so is the modern replacement for pam_tally2.so, tracking failed attempts and locking accounts after a threshold. Together, they meet the security team's requirements when placed in the correct PAM stacks.

Exam trap

The trap here is selecting the deprecated pam_tally2.so for lockout instead of the current pam_faillock.so, which is now the recommended module on modern Linux distributions.

40
MCQeasy

Which of the following correctly describes the purpose of the /etc/shadow file?

A.It stores the list of users who can use sudo.
B.It stores group memberships and group passwords.
C.It stores user account information including UID, GID, and shell.
D.It stores encrypted passwords and password aging fields.
AnswerD

/etc/shadow holds the encrypted password hashes plus password aging fields such as last change, minimum and maximum age, warning period, and account expiry. This separates sensitive hashes from world-readable /etc/passwd, satisfying the question's description of its purpose.

Why this answer

The /etc/shadow file stores encrypted (hashed) user passwords and password aging information such as the date of last password change, minimum/maximum password age, and account expiration. This file is readable only by root to protect password hashes from unauthorized access, unlike /etc/passwd which is world-readable.

Exam trap

The trap here is that candidates confuse the purpose of /etc/shadow with /etc/passwd, mistakenly thinking /etc/shadow stores UID, GID, and shell, when in fact those are in /etc/passwd and /etc/shadow specifically holds password hashes and aging data.

How to eliminate wrong answers

Option A is wrong because the list of users who can use sudo is stored in /etc/sudoers (or /etc/sudoers.d/), not in /etc/shadow. Option B is wrong because group memberships and group passwords are stored in /etc/group and /etc/gshadow, not in /etc/shadow. Option C is wrong because user account information including UID, GID, and shell is stored in /etc/passwd, not in /etc/shadow.

41
MCQeasy

An administrator wants to enforce an account lockout policy after five failed login attempts on a Linux system. Which PAM module should be added to the authentication stack?

A.pam_faillock.so
B.pam_unix.so
C.pam_pwquality.so
D.pam_tally2.so
AnswerA

`pam_faillock.so` counts consecutive failed authentications per account and locks the account once the threshold is reached, satisfying the five-attempt lockout requirement. Configure it via `pam_faillock` in both the `auth` and `account` stacks, since the `account` phase enforces the lockout after the counter trips.

Why this answer

pam_faillock is used for account lockout after failed attempts. pam_unix handles authentication, pam_pwquality checks password strength, pam_tally2 is an older module.

42
MCQhard

A system administrator configures PAM to enforce account lockout after 3 failed login attempts. Which PAM module should be used?

A.pam_faillock
B.pam_pwquality
C.pam_securetty
D.pam_unix
AnswerA

pam_faillock tracks failed authentication attempts per account and locks the account once the configured threshold is reached, satisfying the three-attempt lockout constraint. Unlike pam_tally2, which is deprecated, pam_faillock integrates with the auth and account stacks and supports per-user unlock intervals, making it the current standard module for this enforcement.

Why this answer

pam_faillock is the correct PAM module for enforcing account lockout after a specified number of failed login attempts. It tracks failed authentication attempts per user and can lock the account when the threshold (e.g., 3 attempts) is reached, typically by writing to a tally file like /var/log/faillock.

Exam trap

The trap here is that candidates may confuse pam_faillock with pam_tally2 (a legacy module) or assume pam_unix alone can enforce lockout, but pam_unix lacks built-in lockout tracking and requires pam_faillock or pam_tally2 for that feature.

How to eliminate wrong answers

Option B (pam_pwquality) is wrong because it enforces password quality rules (e.g., length, complexity) during password changes, not account lockout after failed logins. Option C (pam_securetty) is wrong because it restricts root login to terminals listed in /etc/securetty, not lockout policies. Option D (pam_unix) is wrong because it handles standard Unix authentication (e.g., verifying passwords via /etc/shadow) but does not provide account lockout functionality on its own.

43
MCQmedium

A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?

A./etc/pam.d/login with pam_securetty.so
B./etc/pam.d/sshd with pam_unix.so
C./etc/pam.d/sudo with pam_permit.so
D./etc/pam.d/common-password with pam_pwquality.so
AnswerD

The pam_pwquality.so module enforces complexity rules through its ucredit, dcredit and minlen parameters, directly satisfying the policy's uppercase, digit and 12-character requirements. Placed in /etc/pam.d/common-password, it intercepts password changes via the password stack, rejecting non-compliant entries at update time.

Why this answer

The pam_pwquality.so module is specifically designed to enforce password complexity policies such as minimum length, uppercase, digit, and special character requirements. It is configured in the password stack of PAM, typically in /etc/pam.d/common-password on Debian-based systems or /etc/pam.d/system-auth on RHEL-based systems. The options for pam_pwquality (e.g., minlen=12, ucredit=-1, dcredit=-1) directly map to the policy requirements.

Therefore, /etc/pam.d/common-password with pam_pwquality.so is the correct choice.

Exam trap

XK0-006 often tests the confusion between authentication modules (like pam_unix) and password quality modules (like pam_pwquality), or mistakenly selecting a PAM file for a specific service (sshd, login) instead of the common password stack.

How to eliminate wrong answers

Option A is wrong because pam_securetty.so restricts root login to secure TTYs and does not enforce password complexity. Option B is wrong because pam_unix.so handles traditional Unix authentication and password changes but does not provide complexity checking; it relies on other modules for that. Option C is wrong because pam_permit.so is a module that always returns success and is used for granting access without authentication, not for enforcing password policies.

44
MCQeasy

A Linux administrator needs to add a new user named 'jdoe' with a home directory and default shell /bin/bash. Which command should be used?

A.chage -m -s /bin/bash jdoe
B.useradd -m -s /bin/bash jdoe
C.passwd -m -s /bin/bash jdoe
D.usermod -m -s /bin/bash jdoe
AnswerB

The -m flag instructs useradd to create the home directory /home/jdoe, while -s /bin/bash sets the login shell, satisfying both stated requirements. Without -m, no home directory is created, and the default shell would otherwise come from /etc/default/useradd.

Why this answer

The useradd command creates a new user account, and the -m flag creates the home directory while -s /bin/bash sets the login shell. This is the standard Linux utility for adding users with a specified home directory and shell in a single command.

Exam trap

XK0-006 often tests the confusion between useradd (create) and usermod (modify) — candidates must recognize that only useradd can create a new account.

How to eliminate wrong answers

Option A is wrong because chage modifies password aging information (e.g., -m sets minimum days between password changes) and does not create users or set shells. Option C is wrong because passwd manages passwords and does not have -m or -s flags for creating users or setting shells. Option D is wrong because usermod modifies an existing user; it cannot create a new user, so running it for a non-existent 'jdoe' would fail.

45
MCQmedium

A security administrator is hardening a Linux server and wants to verify that the SSH daemon is configured to disallow direct root logins. The administrator has already edited /etc/ssh/sshd_config and set PermitRootLogin no. Which command should the administrator run to ensure the SSH daemon reloads the configuration without terminating existing SSH sessions?

A.sshd -t
B.systemctl restart sshd
C.kill -HUP $(pidof sshd)
D.systemctl reload sshd
AnswerD

This command sends a SIGHUP to the sshd service, causing it to re-read its configuration file while keeping existing connections alive. It is the standard way to apply changes to /etc/ssh/sshd_config without dropping active sessions, which is exactly what the administrator needs to verify the PermitRootLogin setting.

Why this answer

Reloading the sshd service with systemctl reload sshd causes the daemon to re-read its configuration file without dropping existing connections, which is ideal when applying changes like PermitRootLogin no. Testing the syntax with sshd -t is good practice beforehand, but it does not activate the new setting. Restarting would disrupt sessions, and direct kill is less reliable than the systemd-managed reload.

Exam trap

The trap here is assuming that restarting the service is required to apply sshd_config changes, when a reload is sufficient and preserves active sessions.

46
MCQhard

An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?

A.The process is running in permissive mode.
B.The process is running in an unconfined domain.
C.SELinux is disabled.
D.The process is confined by a targeted policy.
AnswerB

The unconfined_t type places the process outside SELinux policy enforcement, so type enforcement rules do not restrict it. Confined domains such as httpd_t are limited by policy; unconfined processes retain standard discretionary access controls only.

Why this answer

The context 'unconfined_u:unconfined_r:unconfined_t:s0' indicates that the process is running in the unconfined domain (unconfined_t). In SELinux, processes in the unconfined domain are not restricted by the targeted policy, meaning they have full access subject to standard Linux permissions.

Exam trap

XK0-006 often tests the misinterpretation of 'unconfined' as permissive mode or disabled SELinux, when it actually refers to the domain type.

How to eliminate wrong answers

Option A is wrong because permissive mode is a global SELinux setting where violations are logged but not enforced; the context itself does not indicate permissive mode. Option C is wrong because if SELinux were disabled, processes would not have SELinux contexts at all. Option D is wrong because a confined process would have a specific domain type (e.g., httpd_t), not unconfined_t.

47
MCQmedium

A system administrator is hardening SSH and needs to disable root login and password authentication. Which two directives should be set in /etc/ssh/sshd_config?

A.PermitRootLogin no and ChallengeResponseAuthentication no
B.DenyUsers root and PasswordAuthentication no
C.PermitRootLogin no and PasswordAuthentication no
D.PermitRootLogin prohibit-password and PasswordAuthentication yes
AnswerC

PermitRootLogin no blocks direct root SSH sessions, forcing administrators to authenticate as unprivileged users before escalating via sudo. PasswordAuthentication no disables password-based logins entirely, requiring key-based authentication instead. Together these directives satisfy both hardening constraints in the stem, eliminating brute-force and credential-guessing attack vectors against the SSH daemon.

Why this answer

Disabling root login and password authentication are two separate directives in sshd_config. PermitRootLogin no prevents direct SSH access for the root user, and PasswordAuthentication no disables password-based logins, forcing the use of key-based authentication. Both directives are required to meet the hardening goal.

Exam trap

The trap here is that candidates confuse ChallengeResponseAuthentication with PasswordAuthentication, or assume DenyUsers is a valid directive for blocking root, when the correct syntax is PermitRootLogin no.

How to eliminate wrong answers

Option A is wrong because ChallengeResponseAuthentication no disables challenge-response authentication (e.g., keyboard-interactive), but it does not disable password authentication; PasswordAuthentication must be explicitly set to no. Option B is wrong because DenyUsers root is not a valid sshd_config directive; the correct directive is PermitRootLogin no. Option D is wrong because PasswordAuthentication yes enables password authentication, which contradicts the requirement to disable it; PermitRootLogin prohibit-password allows root login with key-based authentication but does not disable password authentication for other users.

48
MCQmedium

An administrator wants to generate a self-signed certificate and private key for testing. Which command creates both in one step?

A.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
B.openssl genrsa -out key.pem 2048
C.openssl req -new -x509 -days 365 -key key.pem -out cert.pem
D.openssl x509 -req -in req.pem -signkey key.pem -out cert.pem
AnswerA

The -x509 flag makes openssl req emit a self-signed certificate rather than a CSR, while -newkey rsa:2048 generates the private key in the same invocation. This satisfies the stem's one-step requirement, producing both key.pem and cert.pem without a separate signing command.

Why this answer

The `openssl req -x509 -newkey rsa:2048` command generates a new private key (via `-newkey`) and immediately creates a self-signed X.509 certificate (via `-x509`) in a single step. The `-keyout` and `-out` flags specify the output files for the private key and certificate, respectively, and `-nodes` ensures the private key is not encrypted with a passphrase, which is typical for testing scenarios.

Exam trap

The trap here is that candidates often confuse `openssl req -new` (which creates a CSR) with `openssl req -x509` (which creates a self-signed certificate), leading them to pick option C, which requires a pre-existing key and does not generate both in one step.

How to eliminate wrong answers

Option B is wrong because `openssl genrsa` only creates an RSA private key; it does not generate a certificate, so it fails to produce both artifacts in one step. Option C is wrong because it uses `-key key.pem` to reference an existing private key file, meaning the private key must already exist; it does not create a new private key as part of the command. Option D is wrong because `openssl x509 -req` processes a Certificate Signing Request (CSR) and signs it with a provided key; it requires a pre-existing CSR and private key, so it does not generate both in one step.

49
MCQmedium

A system administrator needs to add an iptables rule to drop incoming TCP traffic on port 22 (SSH) from the IP address 10.0.0.100. Which command should be used?

A.iptables -A INPUT -p udp --dport 22 -s 10.0.0.100 -j DROP
B.iptables -I OUTPUT -p tcp --sport 22 -d 10.0.0.100 -j DROP
C.iptables -A FORWARD -p tcp --dport 22 -s 10.0.0.100 -j DROP
D.iptables -A INPUT -p tcp --dport 22 -s 10.0.0.100 -j DROP
AnswerD

Appending to the INPUT chain with `-A` matches inbound packets, while `-p tcp --dport 22 -s 10.0.0.100` filters TCP destined for port 22 from that source, and `-j DROP` discards them silently. This satisfies the requirement to drop incoming SSH traffic from 10.0.0.100.

Why this answer

iptables -A INPUT -p tcp --dport 22 -s 10.0.0.100 -j DROP is correct because it appends a rule to the INPUT chain that matches TCP packets destined for port 22 (SSH) from source IP 10.0.0.100 and drops them. This precisely implements the requirement to block incoming SSH traffic from that specific IP address. The -p tcp specifies the protocol, --dport 22 matches the destination port, and -s sets the source address.

Exam trap

XK0-006 often tests the confusion between INPUT, OUTPUT, and FORWARD chains, and between source and destination ports; candidates may incorrectly use OUTPUT or FORWARD when the requirement is to block incoming traffic to the local system.

How to eliminate wrong answers

Option A is wrong because it uses -p udp, which matches UDP traffic, but SSH uses TCP; thus it would not block SSH. Option B is wrong because it uses the OUTPUT chain and --sport 22, which would block outgoing SSH traffic from the server to that IP, not incoming traffic. Option C is wrong because it uses the FORWARD chain, which is for packets being routed through the system, not for packets destined to the local system; incoming SSH to the server itself is handled by INPUT.

50
MCQmedium

A Linux administrator is troubleshooting a service that fails to start. The audit.log shows an AVC denial related to the httpd_t domain. The administrator wants to see the full denial message and generate a policy to allow the access. Which two commands should be used in conjunction?

A.auditctl and ausearch
B.ausearch and restorecon
C.aureport and audit2why
D.ausearch and audit2allow
AnswerD

ausearch retrieves the full AVC denial records from the audit log, while audit2allow converts those denials into allow rules for a loadable policy module. Together they reveal the complete denial and generate the targeted SELinux policy.

Why this answer

`ausearch` retrieves the full AVC denial message from the audit log, and `audit2allow` generates a policy module to allow the denied access. Together, they enable the administrator to first identify the exact denial and then create a custom SELinux policy to permit the httpd_t domain's blocked action.

Exam trap

The trap here is that candidates confuse `ausearch` with `aureport` or `auditctl`, or think `restorecon` can fix AVC denials, when in fact only `ausearch` paired with `audit2allow` provides the complete solution for generating a custom policy from a denial message.

How to eliminate wrong answers

Option A is wrong because `auditctl` configures audit rules and does not retrieve denial messages, while `ausearch` alone cannot generate a policy. Option B is wrong because `restorecon` restores default SELinux contexts on files, which does not address AVC denials or generate policies. Option C is wrong because `aureport` summarizes audit events but does not produce a policy, and `audit2why` explains denials but does not generate an allow policy.

51
MCQhard

An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?

A.apparmor_parser -r /etc/apparmor.d/profile
B.aa-status --enforce /etc/apparmor.d/profile
C.aa-enforce /etc/apparmor.d/profile
D.aa-complain /etc/apparmor.d/profile
AnswerC

aa-enforce switches the named AppArmor profile from complain to enforce mode, so the kernel actively denies operations the profile disallows rather than merely logging them. Specifying the profile path targets exactly the service the stem says should be enforcing.

Why this answer

The aa-enforce command is the AppArmor userspace utility that sets a profile to enforce mode, causing the kernel to actively block operations that violate the profile. Running aa-enforce /etc/apparmor.d/profile transitions the specified profile from complain (or unconfined) to enforce. This is the standard way to harden a service after testing its profile in complain mode.

Exam trap

The trap is that candidates confuse apparmor_parser -r (reload) with mode changes — reloading a profile does not change its enforce/complain state, and aa-complain is the inverse of what's needed.

How to eliminate wrong answers

Option A is wrong because apparmor_parser -r reloads a profile from disk but does not change its mode from complain to enforce — the mode is determined by the profile file contents or by aa-complain/aa-enforce. Option B is wrong because aa-status only reports the current AppArmor state; it has no --enforce flag and cannot change profile modes. Option D is wrong because aa-complain does the opposite — it sets a profile to complain mode, which logs violations without blocking them, exactly the state the administrator wants to move away from.

52
MCQhard

An administrator is troubleshooting an AppArmor profile that is blocking a custom application. They want to set the profile to complain mode to gather violations without enforcing. Which command should they use?

A.aa-status
B.aa-complain /path/to/profile
C.apparmor_parser -r /etc/apparmor.d/profile
D.aa-enforce /path/to/profile
AnswerB

`aa-complain` switches an AppArmor profile from enforce to complain mode, logging policy violations without blocking the application. This directly satisfies the administrator's requirement to gather violations without enforcement, unlike `aa-enforce`, which would keep blocking. Passing the profile path targets that specific profile rather than all loaded profiles.

Why this answer

aa-complain sets the profile to complain mode.

53
Multi-Selectmedium

A security audit has identified that several users have excessive sudo privileges. The administrator needs to review and modify sudo access. Which two files or commands would be used? (Choose TWO.)

Select 2 answers
A.chage
B.visudo
C.usermod -G
D./etc/sudoers
E./etc/group
AnswersB, D

`visudo` safely edits the sudoers configuration, validating syntax before saving so a malformed rule cannot lock out sudo access. It satisfies the audit requirement to review and modify excessive privileges by letting the administrator inspect and amend existing user entries, and it respects file locking to prevent concurrent edits.

Why this answer

Option B (visudo) is correct because it is the designated command for safely editing the sudo policy: it locks the sudoers file against concurrent edits, performs syntax checking before saving, and prevents a corrupt sudoers file from breaking sudo access. Option D (/etc/sudoers) is correct because it is the primary sudo policy file that defines which users and groups may run which commands as which target users, so reviewing and modifying excessive sudo privileges requires examining and changing this file. The unmarked options do not belong: chage (A) manages password aging fields such as -M, -m, and -W, not sudo rights; usermod -G (C) changes a user's supplementary group memberships, which only indirectly affects sudo if those groups are referenced in sudoers; and /etc/group (E) lists group memberships but contains no sudo command-authorization rules.

Exam trap

The trap is that candidates pick usermod -G or /etc/group thinking group membership equals sudo access — but sudo privileges are defined in /etc/sudoers, and visudo is the only safe way to edit it.

54
MCQmedium

To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?

A.RootLogin no
B.PermitRootLogin no
C.DenyUsers root
D.AllowUsers root
AnswerB

PermitRootLogin no directly blocks root authentication over SSH, satisfying the requirement to disable root login. The directive accepts values such as yes, no, prohibit-password and forced-commands-only; setting no rejects all root logins regardless of authentication method, which is stricter than prohibit-password. The sshd service must be reloaded for the change to take effect.

Why this answer

The correct directive in /etc/ssh/sshd_config to prevent the root account from logging in over SSH is 'PermitRootLogin no'. This is the exact keyword recognized by OpenSSH's sshd, and setting it to 'no' blocks all root logins regardless of authentication method. After editing the file, the administrator must reload or restart sshd (e.g., systemctl reload sshd) for the change to take effect.

Exam trap

XK0-006 often tests the confusion between similar-sounding directives — candidates must know the exact keyword 'PermitRootLogin' rather than plausible but invalid names like 'RootLogin' or user-list directives like DenyUsers.

How to eliminate wrong answers

Option A is wrong because 'RootLogin' is not a valid sshd_config directive — sshd would ignore it or fail to parse it, leaving root login enabled. Option C is wrong because 'DenyUsers root' is a valid directive but it is used in the context of denying specific users and is not the canonical way to disable root SSH login; more importantly, it is not the directive the question is asking for and can be overridden by AllowUsers ordering. Option D is wrong because 'AllowUsers root' does the opposite — it explicitly permits root to log in, which is the exact behavior the administrator is trying to prevent.

55
MCQmedium

A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?

A.jdoe ALL=(ALL) NOPASSWD: ALL
B.jdoe ALL=(root) /usr/bin/su
C.jdoe ALL= /bin/su -
D.jdoe ALL=(ALL) ALL
AnswerD

The entry jdoe ALL=(ALL) ALL grants jdoe permission to run any command as any user on all hosts, and sudo prompts for jdoe's own password by default. This satisfies both constraints: full root command access without sharing the root password.

Why this answer

The format is 'user host=(runas) commands'. The correct entry grants jdoe full root access with password authentication.

56
Multi-Selecthard

A security audit reveals that a service is running with an incorrect SELinux context. Which two commands can be used to relabel the file or directory to the correct context? (Choose TWO.)

Select 2 answers
A.setenforce 0
B.restorecon -R /path/to/file
C.chcon -t httpd_sys_content_t /path/to/file
D.fixfiles relabel
E.ls -Z
AnswersB, C

The `restorecon -R /path/to/file` command recursively resets SELinux contexts to the values defined in the system's file-context policy, satisfying the requirement to relabel a file or directory to its correct context. Unlike `chcon`, which applies a manually specified context, `restorecon` reads the persistent policy mapping, ensuring the audit finding is resolved durably.

Why this answer

Option B (restorecon -R /path/to/file) is correct because restorecon resets a file or directory's SELinux context to the default defined by the system's policy, and the -R flag applies this recursively to the specified path, which is exactly what is needed to fix an incorrect context. Option C (chcon -t httpd_sys_content_t /path/to/file) is correct because chcon directly changes the SELinux type of a file or directory to the specified context (here httpd_sys_content_t), allowing an administrator to manually set the correct context. Option A (setenforce 0) only switches SELinux to permissive mode and does not relabel anything.

Option D (fixfiles relabel) is a broader relabeling utility typically used to relabel the entire filesystem or all files, not to target a specific file or directory's context. Option E (ls -Z) merely displays SELinux contexts and does not modify them.

Exam trap

XK0-006 often tests the distinction between commands that modify SELinux contexts versus those that only display or change enforcement mode, and candidates may incorrectly choose 'fixfiles relabel' for a single file.

57
MCQmedium

A security administrator needs to configure a Linux server so that all users must use a password of at least 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these requirements?

A./etc/security/pwquality.conf
B./etc/login.defs
C./etc/shadow
D./etc/pam.d/system-auth
AnswerA

The /etc/security/pwquality.conf file is the central configuration file for the pam_pwquality module, which enforces password complexity rules. Parameters like minlen, ucredit, lcredit, dcredit, and ocredit can be set here to require minimum length and character classes. Editing this file applies the policy system-wide for all users when they change their passwords.

Why this answer

Password complexity requirements are enforced by the pam_pwquality PAM module, which reads its settings from /etc/security/pwquality.conf. This file allows administrators to set minimum length and required character classes globally. Other files like login.defs or system-auth serve different purposes and do not contain the specific parameters for password composition.

Exam trap

The trap here is assuming that /etc/pam.d/system-auth holds the password policy parameters; it only references the module, while the actual rules reside in pwquality.conf.

58
MCQeasy

A Linux administrator needs to prevent the root user from logging in via SSH. Which directive should be set in /etc/ssh/sshd_config to accomplish this?

A.PasswordAuthentication no
B.PermitRootLogin no
C.MaxAuthTries 1
D.AllowUsers root
AnswerB

PermitRootLogin no directly disables root authentication over SSH, satisfying the requirement to block root logins. The sshd daemon reads this directive at startup and rejects any authentication attempt for the root account, regardless of password or key. Other values such as prohibit-password still allow key-based root access, so only "no" fully prevents it.

Why this answer

The directive `PermitRootLogin no` in `/etc/ssh/sshd_config` explicitly disallows the root user from authenticating via SSH, regardless of the authentication method used. This is the standard way to block root SSH logins while still allowing other users to connect.

Exam trap

The trap here is that candidates often confuse `PasswordAuthentication no` with blocking root login, not realizing that root could still authenticate via SSH keys or other mechanisms if `PermitRootLogin` is not explicitly set to `no`.

How to eliminate wrong answers

Option A is wrong because `PasswordAuthentication no` disables password-based authentication for all users, but root could still log in using a public key or other methods; it does not specifically prevent root login. Option C is wrong because `MaxAuthTries 1` limits the number of authentication attempts per connection, but it does not prevent root from logging in on the first successful attempt. Option D is wrong because `AllowUsers root` explicitly permits only the root user to log in, which is the opposite of what is needed.

59
MCQmedium

A web server running on port 8080 must be accessible from external networks. The system uses firewalld. Which command opens port 8080/tcp permanently in the default zone?

A.firewall-cmd --zone=public --add-service=8080/tcp --permanent
B.firewall-cmd --permanent --add-port=8080/tcp
C.iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
D.firewall-cmd --add-port=8080/tcp
AnswerB

The --permanent flag writes the rule into firewalld's persistent configuration rather than only the runtime zone, meeting the requirement that the port stay open across reboots or reloads. The --add-port=8080/tcp argument specifies the exact port and protocol in the default zone.

Why this answer

The correct firewalld command is 'firewall-cmd --permanent --add-port=8080/tcp' followed by '--reload'.

60
MCQmedium

A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?

A.setenforce 0
B.setsebool -P httpd_can_network_connect on
C.semanage permissive -a httpd_t
D.restorecon -R /
AnswerA

setenforce 0 switches SELinux from enforcing to permissive mode immediately in the running kernel. In permissive mode, policy violations are logged but not blocked, which is exactly the temporary change requested. The command takes effect without a reboot and does not alter the persistent configuration in /etc/selinux/config.

Why this answer

The setenforce command changes the SELinux mode at runtime. Passing 0 selects permissive mode, where denials are logged but not enforced. This satisfies the requirement to switch temporarily without rebooting.

Persistent changes require editing /etc/selinux/config, but the scenario explicitly asks for a runtime change.

Exam trap

The trap here is confusing a global runtime mode change with per-domain permissive settings or boolean toggles, which affect only specific policy components.

61
MCQeasy

A Linux administrator needs to ensure that user passwords meet a minimum length requirement of 12 characters. The system uses PAM and the pam_pwquality module. Which file should the administrator edit to set the minlen parameter?

A./etc/security/pwquality.conf
B./etc/pam.d/system-auth
C./etc/security/limits.conf
D./etc/login.defs
AnswerA

The pam_pwquality module reads its configuration from /etc/security/pwquality.conf, where parameters like minlen, dcredit, and ucredit are defined. Setting minlen = 12 in this file enforces a minimum password length of 12 characters for all users, assuming the PAM stack includes pam_pwquality.

Why this answer

The pam_pwquality module's parameters, including minlen, are configured in /etc/security/pwquality.conf. This centralized file is read by the module whenever a password is set or changed, provided the PAM stack includes pam_pwquality. Other files like login.defs may contain password aging settings but do not control PAM-based quality checks.

Exam trap

The trap here is assuming that PASS_MIN_LEN in /etc/login.defs controls password length for all changes, when it is only used by certain account creation tools.

62
MCQeasy

A technician needs to ensure a service can listen on TCP port 8443 using firewalld. Which command permanently adds the port to the default zone?

A.firewall-cmd --add-port=8443/tcp --permanent
B.firewall-cmd --add-port=8443 --permanent
C.firewall-cmd --add-port=8443/tcp
D.firewall-cmd --add-service=8443/tcp --permanent
AnswerA

The `--permanent` flag writes the rule to firewalld's persistent configuration rather than only the runtime set, satisfying the requirement to add the port permanently. Without it, the change would vanish on reload or reboot. The command targets the default zone automatically, so no `--zone` argument is needed.

Why this answer

The correct syntax is firewall-cmd --add-port=8443/tcp --permanent. The other options either omit the protocol, use incorrect syntax, or forget --permanent.

63
MCQhard

A Linux administrator is implementing mandatory access control using AppArmor on an Ubuntu server. A custom web application profile is loaded in enforce mode, but the application is failing to write to /var/log/myapp/. The administrator wants to temporarily switch the profile to complain mode to diagnose the issue without disabling AppArmor entirely. Which command should be used?

A.aa-complain /etc/apparmor.d/usr.bin.myapp
B.aa-disable /etc/apparmor.d/usr.bin.myapp
C.aa-status --enforce /etc/apparmor.d/usr.bin.myapp
D.apparmor_parser -R /etc/apparmor.d/usr.bin.myapp
AnswerA

The aa-complain command sets the specified AppArmor profile to complain mode, where violations are logged but not blocked. This allows the application to write to the log directory while generating audit entries that reveal which rules need adjustment. It is the correct tool for temporary diagnosis without unloading the profile.

Why this answer

Switching an AppArmor profile to complain mode is done with aa-complain, which changes the profile's mode so that policy violations are logged rather than denied. This allows the application to function while capturing the necessary audit data to refine the profile. The other commands either unload the profile, disable it permanently, or merely display status, none of which achieve temporary diagnostic logging.

Exam trap

The trap here is confusing complain mode with disabling the profile, when complain mode actually keeps the profile loaded and logs violations instead of blocking them.

64
MCQhard

An administrator runs 'auditctl -w /etc/passwd -p wa -k passwd_changes' to monitor changes to /etc/passwd. Which command should be used to search the audit log for all events related to this watch?

A.ausearch -k passwd_changes
B.auditctl -l -k passwd_changes
C.tail -f /var/log/audit/audit.log | grep passwd_changes
D.aureport -k passwd_changes
AnswerA

ausearch with -k filters the audit log by the rule's key, returning every event tagged passwd_changes. Since the watch was loaded with that exact key, this is the precise selector for retrieving all related events.

Why this answer

The `ausearch -k passwd_changes` command is correct because it searches the audit log for events that were tagged with the key `passwd_changes` when the watch was created via `auditctl -w /etc/passwd -p wa -k passwd_changes`. The `-k` option in `auditctl` assigns a key to the rule, and `ausearch` uses that same key to filter and retrieve matching audit records from `/var/log/audit/audit.log`.

Exam trap

The trap here is that candidates confuse `ausearch` (for searching logs) with `aureport` (for generating summaries) or `auditctl -l` (for listing rules), leading them to pick a command that does not actually retrieve historical audit events.

How to eliminate wrong answers

Option B is wrong because `auditctl -l -k passwd_changes` lists currently loaded audit rules, not search results from the audit log; it would show the rule itself, not events. Option C is wrong because `tail -f /var/log/audit/audit.log | grep passwd_changes` is a raw log tail with grep, which is inefficient and unreliable for structured audit log searching, and it does not use the dedicated `ausearch` tool that properly parses audit records. Option D is wrong because `aureport -k passwd_changes` generates summary reports of audit events, not a detailed event listing; it aggregates data and does not output individual audit records like `ausearch` does.

65
Multi-Selectmedium

A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)

Select 2 answers
A.Set MaxAuthTries to 10
B.Set UsePAM to no
C.Set X11Forwarding to yes
D.Set PermitRootLogin to no
E.Set PasswordAuthentication to no
AnswersD, E

Disabling direct root logins forces administrators to authenticate as a normal user and then escalate privileges, which adds accountability and reduces the impact of brute-force attacks against the root account. This is a standard SSH hardening measure and directly limits a high-value authentication path on the web server.

Why this answer

Disabling root login and password authentication are two widely recommended SSH hardening measures. They force administrators to use named accounts and key-based authentication, reducing the effectiveness of brute-force and credential-stuffing attacks. The other listed changes either increase exposure or weaken authentication controls, so they do not support the goal of reducing the SSH attack surface.

Exam trap

The trap here is assuming that increasing MaxAuthTries or enabling X11Forwarding improves security, when both actually expand the attack surface.

66
Multi-Selectmedium

An administrator wants to harden SSH access by implementing the following: disallow root login, disable password authentication, and limit the number of authentication attempts. Which three configuration directives should be set in /etc/ssh/sshd_config? (Choose THREE.)

Select 3 answers
A.PermitRootLogin no
B.Port 22
C.PermitEmptyPasswords no
D.PasswordAuthentication no
E.MaxAuthTries 3
AnswersA, D, E

PermitRootLogin no blocks direct root logins over SSH, satisfying the stem's first hardening requirement. Setting it to no forces administrators to authenticate as an unprivileged user first, typically escalating via sudo, which removes a high-value brute-force target.

Why this answer

Option A, PermitRootLogin no, is correct because it directly disallows direct root logins over SSH, forcing administrators to authenticate as a regular user and then escalate privileges, which is the stated hardening goal. Option D, PasswordAuthentication no, is correct because it disables password-based authentication, requiring key-based (or other non-password) authentication methods instead. Option E, MaxAuthTries 3, is correct because it limits the number of authentication attempts allowed per connection, throttling brute-force guessing as requested.

Option B, Port 22, is not correct because it merely sets the default SSH listening port and does not harden authentication. Option C, PermitEmptyPasswords no, is not correct here because it only prevents logins with blank passwords, which is unrelated to the three specific requirements of disallowing root login, disabling password authentication, and limiting authentication attempts.

67
MCQmedium

An administrator notices repeated failed login attempts in /var/log/secure. The company policy requires account lockout after 5 failed attempts within 15 minutes. Which PAM module and configuration can enforce this?

A.pam_unix.so with remember=5
B.pam_pwquality.so with minlen=5
C.pam_limits.so with maxlogins=5
D.pam_faillock.so with deny=5 unlock_time=900
AnswerD

pam_faillock.so tracks failed authentication attempts per account and enforces lockout once the threshold is crossed. Setting deny=5 satisfies the five-attempt policy, while unlock_time=900 locks the account for fifteen minutes, matching the required window. Unlike pam_tally2, it integrates with faillock and supports per-user tally files.

Why this answer

Pam_faillock.so is the PAM module specifically designed to track failed login attempts and enforce account lockout policies. The `deny=5` parameter sets the threshold to 5 failures, and `unlock_time=900` sets the lockout duration to 900 seconds (15 minutes), matching the policy requirement exactly.

Exam trap

The trap here is confusing password policy modules (pam_pwquality.so, pam_unix.so) or session limits (pam_limits.so) with the dedicated account lockout module pam_faillock.so, leading candidates to select options that address different security controls.

How to eliminate wrong answers

Option A is wrong because pam_unix.so with `remember=5` controls password history (preventing reuse of the last 5 passwords), not account lockout after failed logins. Option B is wrong because pam_pwquality.so with `minlen=5` enforces password complexity and minimum length, not failed login attempt tracking. Option C is wrong because pam_limits.so with `maxlogins=5` limits the maximum number of concurrent login sessions for a user, not the number of failed attempts before lockout.

68
MCQhard

A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?

A.Encrypt the file with a tool such as gpg or openssl enc using a key that is never stored on the server.
B.Set the file mode to 0660 and change its group owner to payroll.
C.Place the file on a filesystem mounted with the noexec and nodev options.
D.Apply the immutable attribute to the file with chattr +i /srv/payroll/ledger.db.
AnswerA

When the file is encrypted and the decryption key resides only off the server, possession of root on that host yields nothing but ciphertext. Access control is enforced by cryptography rather than by the kernel's permission model, so even the superuser cannot recover the ledger contents without the external key.

Why this answer

Traditional Unix permissions, including restrictive modes and special attributes, are enforced by the kernel, and root is deliberately exempt from those checks. The only way to guarantee that even root cannot read a file's contents is to encrypt it and keep the decryption key off the server, shifting enforcement from the permission model to cryptography that root cannot bypass.

Exam trap

The trap here is assuming that restrictive modes, chattr +i, or mount options can constrain root, when the kernel's discretionary access control always exempts UID 0 from read and write permission checks.

69
MCQeasy

A Linux administrator needs to add a new user named 'jdoe' with a home directory and bash shell. Which command accomplishes this?

A.groupadd -u jdoe -s /bin/bash
B.useradd -m -s /bin/bash jdoe
C.adduser -h /home/jdoe -s bash jdoe
D.usermod -m -s /bin/bash jdoe
AnswerB

useradd -m creates the home directory and -s /bin/bash sets the login shell, satisfying both stated requirements in a single command. Without -m, no home directory is created; without -s, the system default shell applies.

Why this answer

The useradd command creates a new user, and the -m flag creates the home directory, -s sets the shell. useradd -m -s /bin/bash jdoe is correct.

70
MCQmedium

A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?

A.chacl -l /usr/bin/ping
B.getfacl /usr/bin/ping
C.lsattr /usr/bin/ping
D.getcap /usr/bin/ping
AnswerD

getcap reads and displays the file capabilities stored in the security.capability extended attribute of a binary. For /usr/bin/ping, it would report cap_net_raw=ep, confirming the binary can open raw sockets without setuid root. This is exactly the inspection the administrator needs to verify least-privilege configuration on the ping utility.

Why this answer

File capabilities allow a binary to perform privileged operations without being setuid root. The getcap command reads the security.capability extended attribute and reports capabilities such as cap_net_raw. Inspecting /usr/bin/ping with getcap confirms whether it can open raw sockets under least privilege, which is the goal of the administrator's verification.

Exam trap

The trap here is confusing file capabilities with POSIX ACLs or filesystem attributes, leading to tools like getfacl or lsattr instead of getcap.

71
MCQmedium

An administrator is hardening SSH and wants to disable root login and only allow users in the 'sshusers' group. Which two directives should be set in /etc/ssh/sshd_config?

A.DenyRootLogin yes and AllowGroups sshusers
B.PermitRootLogin prohibit-password and AllowGroups sshusers
C.PermitRootLogin no and AllowGroups sshusers
D.PermitRootLogin no and AllowUsers sshusers
AnswerC

PermitRootLogin no blocks direct superuser SSH access, forcing administrators to log in as themselves before elevating. AllowGroups sshusers restricts authentication to members of that group via the AllowGroups directive, satisfying both hardening constraints. DenyUsers or AllowUsers would not reference group membership.

Why this answer

The directive `PermitRootLogin no` explicitly disallows root login via SSH, and `AllowGroups sshusers` restricts SSH access to only members of the 'sshusers' group. This combination meets both requirements: disabling root login and limiting access to a specific group. The `AllowGroups` directive is group-based, unlike `AllowUsers`, which is user-based.

Exam trap

The trap here is confusing `AllowGroups` with `AllowUsers` — candidates often pick `AllowUsers sshusers` thinking it restricts to the group, but it actually restricts to a user named 'sshusers', not group membership.

How to eliminate wrong answers

Option A is wrong because `DenyRootLogin` is not a valid directive in sshd_config; the correct directive is `PermitRootLogin`. Option B is wrong because `PermitRootLogin prohibit-password` only disables password-based root login but still allows root login via public key authentication, which does not fully disable root login as required. Option D is wrong because `AllowUsers sshusers` would only allow a user literally named 'sshusers', not members of the 'sshusers' group; the correct group-based directive is `AllowGroups`.

72
MCQeasy

Which file contains user password hashes and aging information on a Linux system?

A./etc/shadow
B./etc/group
C./etc/passwd
D./etc/gshadow
AnswerA

/etc/shadow stores the hashed passwords alongside ageing fields such as last change, minimum, maximum and warning days, which /etc/passwd does not hold. It is readable only by root, restricting hash exposure. This satisfies the requirement for both password hashes and ageing information in one file.

Why this answer

The /etc/shadow file stores user password hashes along with password aging information, such as the last password change date, minimum and maximum password age, warning period, and inactivity lockout. This file is readable only by root (or privileged processes) to protect the hashed passwords from unauthorized access, unlike /etc/passwd which is world-readable.

Exam trap

The trap here is that candidates often confuse /etc/passwd with /etc/shadow, mistakenly thinking that /etc/passwd still stores password hashes, but modern Linux systems store them only in /etc/shadow for security.

How to eliminate wrong answers

Option B is wrong because /etc/group stores group membership information, not password hashes or aging data. Option C is wrong because /etc/passwd contains user account details (like UID, GID, home directory) and traditionally held password hashes, but on modern Linux systems it uses an 'x' placeholder and defers to /etc/shadow for security. Option D is wrong because /etc/gshadow stores group password hashes and group administrator information, not user password hashes or aging data.

73
Multi-Selectmedium

A security policy requires that user passwords must be changed every 60 days, and users should be warned 7 days before expiration. Which two chage commands set these requirements for user 'jsmith'? (Choose TWO.)

Select 2 answers
A.chage -M 60 jsmith
B.chage -E 60 jsmith
C.chage -W 7 jsmith
D.chage -m 60 jsmith
E.chage -I 7 jsmith
AnswersA, C

`chage -M 60 jsmith` sets the maximum password age to 60 days, satisfying the policy's mandatory 60-day rotation. The `-M` flag defines the exact interval between required changes, after which the account forces a new password. It does not configure the 7-day warning, so a second command using `-W 7` is still needed.

Why this answer

Option A, `chage -M 60 jsmith`, is correct because the `-M` flag sets the maximum number of days a password remains valid before it must be changed, which directly enforces the 60-day password expiration requirement. Option C, `chage -W 7 jsmith`, is correct because the `-W` flag sets the number of days of advance warning before the password expires, satisfying the requirement to warn users 7 days ahead. Option B (`-E 60`) sets an account expiration date, not a password change interval, so it does not meet the policy.

Option D (`-m 60`) sets the minimum days between password changes, which would prevent users from changing passwords for 60 days rather than requiring a change every 60 days. Option E (`-I 7`) sets the number of inactive days after password expiration before the account is locked, which is unrelated to the warning requirement.

Exam trap

XK0-006 often tests the confusion between -m (minimum) and -M (maximum) — candidates frequently swap them, and the case sensitivity is the exact trap.

74
MCQeasy

A Linux administrator needs to configure the system so that all users must use a minimum password length of 12 characters. The administrator edits /etc/security/pwquality.conf. Which line should be added or modified to enforce this requirement?

A.password requisite pam_pwquality.so minlen=12
B.min_password_length = 12
C.PASS_MIN_LEN 12
D.minlen = 12
AnswerD

In /etc/security/pwquality.conf, the minlen parameter specifies the minimum acceptable length for a new password. Setting minlen = 12 enforces that all new passwords are at least 12 characters long. This is the correct directive for the pwquality PAM module, which is commonly used on modern Linux distributions.

Why this answer

The pwquality.conf file uses the minlen directive to set the minimum password length. Adding minlen = 12 ensures that the pam_pwquality module enforces a 12-character minimum for new passwords, provided the module is enabled in the PAM configuration.

Exam trap

The trap here is mixing up parameters from different configuration files, such as PASS_MIN_LEN from login.defs, with the correct minlen from pwquality.conf.

75
MCQhard

A Linux server has SELinux enforcing and a custom application needs to write to /var/log/app.log. The audit log shows 'avc: denied { write } for pid=1234'. After verifying that the application runs in the correct domain, which command should be used to allow the write access by generating a policy module?

A.ausearch -m avc | audit2allow -M myapp
B.chcon -t var_log_t /var/log/app.log
C.setsebool -P httpd_unified 1
D.restorecon -v /var/log/app.log
AnswerA

ausearch extracts the AVC denial records from the audit log and pipes them into audit2allow, which translates the denials into allow rules and compiles them into a loadable module named myapp. This satisfies the requirement to generate a policy module granting the write access.

Why this answer

The audit2allow workflow is the standard way to convert SELinux AVC denial messages into a loadable policy module. Piping ausearch output into audit2allow -M myapp generates a .te source file and compiles it into a myapp.pp module that can be installed with semodule -i, granting exactly the denied write permission.

Exam trap

XK0-006 often tests the distinction between labeling commands (chcon, restorecon), boolean toggles (setsebool), and policy generation (audit2allow), so candidates must recognize that only audit2allow produces a policy module.

How to eliminate wrong answers

Option B is wrong because chcon changes the SELinux context of a file, which alters labeling but does not generate a policy module and may not resolve a domain-level denial. Option C is wrong because setsebool toggles an existing boolean (httpd_unified) and is unrelated to a custom application's write denial. Option D is wrong because restorecon resets a file's context to its default policy value, which does not grant new write permissions to the application's domain.

Page 1 of 2 · 109 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.