CompTIA Linux+ (XK0-006)SecurityMedium
A compliance policy requires that all new local user passwords be at least 14 characters long, enforced through PAM at password creation time. Which file and setting should the administrator configure to meet this requirement?
- A/etc/login.defs with 'PASS_MIN_LEN 14'
- B/etc/sudoers with 'Defaults passwd_min_length=14'
- C/etc/pam.d/system-auth with 'password requisite pam_faillock.so'
- D/etc/security/pwquality.conf with 'minlen = 14'
Show answer & explanationAnswer & explanation
Correct answer: D. /etc/security/pwquality.conf with 'minlen = 14'
pam_pwquality, configured via /etc/security/pwquality.conf, is the module invoked during password change/creation on modern distributions to enforce complexity rules such as minlen. login.defs' PASS_MIN_LEN is a legacy setting largely unused by PAM-based password quality checks, pam_faillock handles lockouts (not length), and sudoers has no such directive.
Why the other options are wrong
- A. PASS_MIN_LEN in login.defs is a legacy setting not enforced by pam_pwquality on modern systems.
- B. sudoers has no passwd_min_length directive; it governs sudo behavior, not password policy.
- C. pam_faillock manages failed login lockouts, not password length or complexity.
pam_pwquality Password Complexity
pam_pwquality is a PAM module that enforces password strength rules (length, character classes) configured in /etc/security/pwquality.conf, typically invoked from /etc/pam.d/system-auth or password-auth.
- minlen sets minimum password length
- dcredit/ucredit/lcredit/ocredit control required character classes
- Configured file: /etc/security/pwquality.conf
- Invoked via 'password requisite pam_pwquality.so' in PAM stack
Memory trick: 'pwquality' = the password's quality inspector, checks length before approval.