Courseiva
System Management →hardMultiple Choice

XK0-006 System Management Practice Question

Given an ACL entry 'u:john:rwx' on a file, which command would remove only the ACL entry for user john without affecting other ACL entries?

⚠ Common exam trap

XK0-006 often tests the distinction between modifying an ACL entry to zero permissions (-m u:user:-) and actually deleting the entry (-x u:user) — candidates pick -m because it looks like it removes access, but the entry remains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

setfacl -x u:john /path/to/file

The setfacl -x u:john /path/to/file command removes only the ACL entry for user john while leaving all other ACL entries (group entries, mask, other users) intact. The -x flag specifically deletes the named entry, which is exactly what the question requires. This is the surgical removal operation in the setfacl toolkit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    setfacl -k /path/to/file

    Why it's wrong here

    setfacl -k removes the default ACL entries on a directory, not a named user entry. It is tempting because it deletes ACL data, but default ACLs apply only to directories for inheritance; the file's u:john entry persists, so the command fails the requirement.

  • ✗

    setfacl -m u:john:- /path/to/file

    Why it's wrong here

    setfacl -m modifies john's entry to an empty permission set rather than deleting it, so the entry remains present with no effective rights. It is tempting because it targets only john, but the ACL entry persists, and the question requires removal of the entry itself.

  • ✓

    setfacl -x u:john /path/to/file

    Why this is correct

    setfacl -x removes the specified ACL entry only, leaving other entries intact. Targeting u:john deletes just john's entry, satisfying the requirement to remove that single entry without disturbing the remaining access ACL or default ACL entries on the file.

  • ✗

    setfacl -b /path/to/file

    Why it's wrong here

    setfacl -b strips all extended ACL entries plus the mask, removing every user and group entry rather than only john's. It is tempting as the obvious removal command, but it eliminates other ACL entries too, violating the requirement to leave the remaining entries intact.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.