XK0-006 Security Practice Question
Which of the following correctly describes the purpose of the /etc/shadow file?
⚠ Common exam trap
Many exam-takers confuse the purpose of /etc/shadow with /etc/passwd, mistakenly thinking /etc/shadow stores UID, GID, and shell, when in fact those are in /etc/passwd and /etc/shadow specifically holds password hashes and aging data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It stores encrypted passwords and password aging fields.
The /etc/shadow file stores encrypted (hashed) user passwords and password aging information such as the date of last password change, minimum/maximum password age, and account expiration. This file is readable only by root to protect password hashes from unauthorized access, unlike /etc/passwd which is world-readable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It stores the list of users who can use sudo.
Why it's wrong here
/etc/shadow stores hashed account passwords and ageing fields, not sudo authorisation. Sudo permissions live in /etc/sudoers, edited with visudo, or in files under /etc/sudoers.d. This option would fit a question asking where sudo privileges are defined, which is why it distracts.
- ✗
It stores group memberships and group passwords.
Why it's wrong here
Group memberships and group passwords belong in /etc/group and /etc/gshadow. /etc/shadow holds per-user password hashes and ageing data. The option tempts because gshadow mirrors shadow's restricted-permission design, but the question asks specifically about the user password database.
- ✗
It stores user account information including UID, GID, and shell.
Why it's wrong here
That describes /etc/passwd, which holds UID, GID, home directory and shell. /etc/shadow stores hashed passwords and ageing fields, readable only by root. The option tempts because both files hold account data, but the split exists precisely to hide password hashes from unprivileged reads.
- ✓
It stores encrypted passwords and password aging fields.
Why this is correct
/etc/shadow holds the encrypted password hashes plus password aging fields such as last change, minimum and maximum age, warning period, and account expiry. This separates sensitive hashes from world-readable /etc/passwd, satisfying the question's description of its purpose.
Go deeper
Related to this question
Learn chapter
File Transfer and Remote Access
Key term
passwd
passwd is a command-line utility used on Linux and Unix-like systems to change a user's password, typically stored in an encrypted format in the /etc/shadow file.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.