CompTIA Linux+ (XK0-006)SecurityHard
An administrator is preparing to encrypt a new LUKS-protected partition, /dev/sdb1, for a critical database server. Before deploying it into production, the administrator wants a way to recover the volume if the LUKS header ever becomes corrupted. Which command should be run?
- Acryptsetup luksDump /dev/sdb1
- Bcryptsetup luksAddKey /dev/sdb1
- Cdd if=/dev/sdb1 of=/root/sdb1-full-backup.img
- Dcryptsetup luksHeaderBackup /dev/sdb1 --header-backup-file /root/sdb1-header.img
Show answer & explanationAnswer & explanation
Correct answer: D. cryptsetup luksHeaderBackup /dev/sdb1 --header-backup-file /root/sdb1-header.img
The LUKS header contains the master key metadata and keyslots required to unlock the volume; if it becomes corrupted, the entire encrypted volume becomes inaccessible even with a correct passphrase. cryptsetup luksHeaderBackup creates a dedicated backup of just this header for disaster recovery.
Why the other options are wrong
- A. luksDump only displays header information on screen; it does not create a recoverable backup file.
- B. luksAddKey adds an additional passphrase/keyslot but does not back up the header itself.
- C. A full dd image backup of the entire partition is far larger and unnecessary just to protect the header; it's not the standard recovery approach for header corruption specifically.
LUKS Header Backup
The LUKS header stores encryption metadata and keyslots; backing it up with cryptsetup luksHeaderBackup protects against data loss if the header becomes corrupted or overwritten.
- Command: cryptsetup luksHeaderBackup <device> --header-backup-file <file>
- Restore with cryptsetup luksHeaderRestore
- Header backups should be stored securely since they can expose keyslot data to attack if a valid passphrase is later guessed
Memory trick: Header backup = saving the vault's combination dial separately from the vault.