CompTIA Linux+ (XK0-006)SecurityHard

An administrator is preparing to encrypt a new LUKS-protected partition, /dev/sdb1, for a critical database server. Before deploying it into production, the administrator wants a way to recover the volume if the LUKS header ever becomes corrupted. Which command should be run?

  1. Acryptsetup luksDump /dev/sdb1
  2. Bcryptsetup luksAddKey /dev/sdb1
  3. Cdd if=/dev/sdb1 of=/root/sdb1-full-backup.img
  4. Dcryptsetup luksHeaderBackup /dev/sdb1 --header-backup-file /root/sdb1-header.img
Show answer & explanation

Correct answer: D. cryptsetup luksHeaderBackup /dev/sdb1 --header-backup-file /root/sdb1-header.img

The LUKS header contains the master key metadata and keyslots required to unlock the volume; if it becomes corrupted, the entire encrypted volume becomes inaccessible even with a correct passphrase. cryptsetup luksHeaderBackup creates a dedicated backup of just this header for disaster recovery.

Why the other options are wrong

  • A. luksDump only displays header information on screen; it does not create a recoverable backup file.
  • B. luksAddKey adds an additional passphrase/keyslot but does not back up the header itself.
  • C. A full dd image backup of the entire partition is far larger and unnecessary just to protect the header; it's not the standard recovery approach for header corruption specifically.

LUKS Header Backup

The LUKS header stores encryption metadata and keyslots; backing it up with cryptsetup luksHeaderBackup protects against data loss if the header becomes corrupted or overwritten.

  • Command: cryptsetup luksHeaderBackup <device> --header-backup-file <file>
  • Restore with cryptsetup luksHeaderRestore
  • Header backups should be stored securely since they can expose keyslot data to attack if a valid passphrase is later guessed

Memory trick: Header backup = saving the vault's combination dial separately from the vault.

More Security questions