SSCP Systems and Application Security Practice Question
A Linux administrator is hardening a server. Which TWO commands are used to manage file permissions? (Select TWO.)
⚠ Common exam trap
SSCP often tests whether candidates confuse user account management commands (usermod, passwd, groupadd) with file permission commands (chmod, chown) — the question's 'file permissions' phrasing is the key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chmod
Option D, chmod, is correct because it directly manages file permissions by changing the read, write, and execute bits (the mode) for the owner, group, and others on files and directories, using symbolic or octal notation. Option E, chown, is correct because it manages file ownership, changing the owning user and/or group of a file, which is a core part of file permission management since permissions are evaluated against the owner and group. Option A, usermod, is incorrect because it modifies user account attributes such as group membership, home directory, and shell, not file permissions. Option B, passwd, is incorrect because it manages user authentication passwords, not file permissions. Option C, groupadd, is incorrect because it creates new groups in the system, not file permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
usermod
Why it's wrong here
usermod modifies user account attributes such as group membership, shell and home directory; it never touches file permission bits. It is tempting because group membership changes can indirectly affect access, but chmod and chown are the commands that actually set mode bits and ownership on files.
- ✗
passwd
Why it's wrong here
passwd changes a user's authentication password or its expiry settings; it does not read or write file mode bits. It is tempting because account credentials underpin access control, but chmod and chown are the commands that actually manage file permissions.
- ✗
groupadd
Why it's wrong here
groupadd creates a new group entry in /etc/group; it assigns no permissions to any file. It is tempting because permissions are granted to groups, so creating one feels related, but chmod and chown are what set mode bits and ownership on files.
- ✓
chmod
Why this is correct
chmod alters the read, write and execute bits of a file's permission mode, applying symbolic or octal changes to owner, group and others. Hardening requires tightening these access bits, so chmod directly satisfies the task of managing file permissions on the server.
- ✓
chown
Why this is correct
chown changes a file's owning user and group, which underpins permission management because access bits are evaluated against ownership. Reassigning ownership to a privileged account or restricted group removes excessive access, satisfying the hardening requirement to manage file permissions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.