Courseiva

XK0-006 · topic practice

Security practice questions

The Security domain of CompTIA Linux+ XK0-006 covers host hardening and access control on Linux systems. Expect scenario questions on SELinux and AppArmor modes, user account and password aging with useradd, passwd, and chage, file permissions and ownership, sudo configuration, and SSH and firewall basics. Items ask you to pick the exact command or file that produces a described state.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security

What the exam tests

What to know about Security

Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.

Switching AppArmor profiles between complain and enforce mode with aa-complain and aa-enforce

Reading SELinux state with getenforce and sestatus, and adjusting it via setenforce or config files

Creating users with useradd, setting shells and home directories, and forcing password changes with chage

Managing sudo privileges, file ownership and permissions, and SSH or firewall access rules

Watch out for

Common Security exam traps

  • ▸Confusing SELinux and AppArmor tooling, or assuming setenforce changes persist across reboots when it only alters runtime mode
  • ▸Using usermod or passwd when the task actually requires chage to expire a password or set aging policy
  • ▸Forgetting that useradd alone does not set a password, so the account stays locked until passwd or chpasswd runs

Practice set

Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Security explanation →

An administrator needs to allow incoming TCP traffic on port 8443 using firewalld. Which command should be used to make this change persistent?

Question 2mediummultiple choice
Read the full Security explanation →

A system is running SELinux in enforcing mode. A custom application needs to write to /var/log/app.log. The log file shows the correct context, but access is denied. What is the most likely cause?

Question 3easymultiple choice
Read the full Security explanation →

Which command displays the current SELinux mode?

Question 4mediummultiple choice
Read the full Security explanation →

An administrator wants to audit all attempts to access the file /etc/shadow. Which auditctl command should be used?

Question 5easymultiple choice
Read the full Security explanation →

Which command displays the last successful login times for all users?

Question 6mediummultiple choice
Read the full Security explanation →

A technician needs to generate a self-signed certificate for an internal web server. Which OpenSSL command creates a new private key and a certificate signing request (CSR) in one step?

Question 7mediummulti select
Read the full Security explanation →

A Linux administrator is troubleshooting a firewall issue using nftables. The ruleset is complex. Which two commands are useful for listing the current ruleset and adding a new rule? (Choose TWO.)

Question 8easymultiple choice
Read the full Security explanation →

A Linux administrator needs to ensure that user passwords expire after 90 days. Which command should be used to enforce this policy?

Question 9mediummultiple choice
Read the full Security explanation →

A security auditor notices that a service account's password never expires. The company policy requires password rotation every 60 days. Which command will enforce this policy for the service account?

Question 10hardmultiple choice
Read the full Security explanation →

A system administrator needs to configure PAM to lock a user account after 5 failed login attempts for 15 minutes. Which two PAM modules and configuration lines are appropriate? (Select TWO.)

Question 11mediummultiple choice
Read the full Security explanation →

A Linux technician is configuring a firewall with firewalld. The organization requires that SSH services be available only on the internal network zone (10.0.0.0/8). Which command should be used to add this rule permanently?

Question 12easymultiple choice
Read the full Security explanation →

Which command displays the current SELinux mode?

Question 13hardmultiple choice
Read the full Security explanation →

A Linux administrator needs to configure auditing to monitor changes to the /etc/passwd file. Which auditctl command should be used?

Question 14mediummultiple choice
Read the full Security explanation →

A technician needs to create a self-signed certificate and private key for a web server. Which OpenSSL command should be used?

Question 15mediummulti select
Read the full Security explanation →

A security audit reveals that user accounts remain active after employees leave the company. Which TWO commands should be used to disable an account immediately?

Question 16hardmulti select
Read the full Security explanation →

An administrator is configuring AppArmor for a custom application. Which THREE commands are used to manage AppArmor profiles?

Question 17hardmulti select
Read the full Security explanation →

An administrator needs to configure iptables to allow incoming SSH traffic only from the 10.0.0.0/8 network and drop all other incoming traffic except established connections. Which TWO rules are necessary?

Question 18easymultiple choice
Read the full Security explanation →

An administrator needs to add a new user named 'jdoe' with a home directory and default group. Which command should be used?

Question 19mediummultiple choice
Read the full Security explanation →

An administrator notices that a non-root user 'alice' can run commands as root without being in the sudoers file. Which group membership could allow this?

Question 20mediummultiple choice
Read the full Security explanation →

A firewall administrator wants to add a rule to allow incoming SSH traffic (port 22) using firewalld. Which command correctly adds this rule to the default zone permanently?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security sessions

Start a Security only practice session

Every question in these sessions is drawn from the Security domain — nothing else.

Related practice questions

Related XK0-006 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the XK0-006 exam test about Security?
Be able to identify and run the exact command that changes a security state: aa-enforce for AppArmor, getenforce or setenforce for SELinux, chage for password expiry, useradd for account creation. The most important thing is matching the requested end state to the correct tool rather than a similar-looking one.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other XK0-006 topics?
Use the topic links above to move to related areas, or go back to the XK0-006 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the XK0-006 exam covers. They are not copied from any real exam or dump site.