XK0-006 Security Practice Question
Which file contains the password aging information such as minimum and maximum days between password changes?
⚠ Common exam trap
XK0-006 often tests the confusion between /etc/login.defs (system-wide defaults for new accounts) and /etc/shadow (per-user actual aging data), causing candidates to pick login.defs when the question asks where the aging information is stored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/shadow
The /etc/shadow file stores encrypted password hashes along with password aging fields: the date of last password change, minimum days before change allowed, maximum days the password is valid, warning days before expiration, inactivity days, and account expiration date. These aging parameters are set by chage or passwd and are enforced by PAM. /etc/passwd no longer stores password hashes on modern systems and does not contain aging fields.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
/etc/shadow
Why this is correct
/etc/shadow stores per-user password aging fields, including minimum days, maximum days, warning period and expiry, alongside the hashed password. This directly satisfies the stem's requirement for minimum and maximum days between password changes, unlike /etc/passwd, which holds account data but no aging constraints.
- ✗
/etc/security/limits.conf
Why it's wrong here
Password aging (PASS_MAX_DAYS, PASS_MIN_DAYS) lives in /etc/login.defs and per-user /etc/shadow, not here. limits.conf sets resource limits such as nproc and nofile via PAM, so it would be the right file when capping processes or open files per user or group.
- ✗
/etc/passwd
Why it's wrong here
/etc/passwd holds account attributes such as username, UID, GID, home directory and login shell, with a placeholder in the password field. Password aging fields (minimum, maximum, warning, inactivity) live in /etc/shadow, which is readable only by root.
- ✗
/etc/login.defs
Why it's wrong here
/etc/login.defs supplies system-wide defaults for useradd and related tools, such as PASS_MAX_DAYS, but per-account aging values are stored in /etc/shadow. The question asks which file contains the aging information itself, not the defaults applied when creating accounts.
Go deeper
Related to this question
Learn chapter
File Permissions and Ownership
Key term
PAM
Privileged Access Management (PAM) is a security framework that controls, monitors, and audits access to critical systems and accounts with elevated permissions.
Key term
passwd
passwd is a command-line utility used on Linux and Unix-like systems to change a user's password, typically stored in an encrypted format in the /etc/shadow file.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.