XK0-006 System Management Practice Question
Given an ACL entry 'u:john:rwx' on a file, which command would remove only the ACL entry for user john without affecting other ACL entries?
⚠ Common exam trap
XK0-006 often tests the distinction between modifying an ACL entry to zero permissions (-m u:user:-) and actually deleting the entry (-x u:user) — candidates pick -m because it looks like it removes access, but the entry remains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
setfacl -x u:john /path/to/file
The setfacl -x u:john /path/to/file command removes only the ACL entry for user john while leaving all other ACL entries (group entries, mask, other users) intact. The -x flag specifically deletes the named entry, which is exactly what the question requires. This is the surgical removal operation in the setfacl toolkit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
setfacl -k /path/to/file
Why it's wrong here
setfacl -k removes the default ACL entries on a directory, not a named user entry. It is tempting because it deletes ACL data, but default ACLs apply only to directories for inheritance; the file's u:john entry persists, so the command fails the requirement.
- ✗
setfacl -m u:john:- /path/to/file
Why it's wrong here
setfacl -m modifies john's entry to an empty permission set rather than deleting it, so the entry remains present with no effective rights. It is tempting because it targets only john, but the ACL entry persists, and the question requires removal of the entry itself.
- ✓
setfacl -x u:john /path/to/file
Why this is correct
setfacl -x removes the specified ACL entry only, leaving other entries intact. Targeting u:john deletes just john's entry, satisfying the requirement to remove that single entry without disturbing the remaining access ACL or default ACL entries on the file.
- ✗
setfacl -b /path/to/file
Why it's wrong here
setfacl -b strips all extended ACL entries plus the mask, removing every user and group entry rather than only john's. It is tempting as the obvious removal command, but it eliminates other ACL entries too, violating the requirement to leave the remaining entries intact.
Visual reference
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
setfacl
setfacl is a Linux/Unix command used to set Access Control Lists on files and directories, providing more detailed permission control beyond the standard owner-group-others model.
Key term
ACL
An Access Control List is a set of rules that determines who or what can access specific network resources or data.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.