A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?
`pam_pwhistory` stores previous password hashes in `/etc/security/opasswd` and compares each new password against them, rejecting any match. The `remember=5` directive retains the last five hashes, directly satisfying the policy's no-reuse constraint for the previous five passwords.
Why this answer
The pam_pwhistory module records previous password hashes and enforces password reuse restrictions via the remember directive. Setting remember=5 prevents users from reusing any of their last five passwords, exactly matching the policy requirement.
Exam trap
XK0-006 often tests the confusion between account lockout modules (pam_faillock, pam_tally2) and password history modules (pam_pwhistory), so candidates must map 'reuse' to remember, not deny.
How to eliminate wrong answers
Option A is wrong because pam_faillock with deny=5 locks accounts after five failed login attempts; it has nothing to do with password history. Option C is wrong because pam_tally2 also counts failed login attempts (and is deprecated in favor of pam_faillock), not password reuse. Option D is wrong because pam_pwquality enforces complexity rules (length, character classes) and does not support a remember directive for password history.