CompTIA Linux+ (XK0-006)SecurityMedium
A technician needs to add a second passphrase to an already-encrypted LUKS partition, /dev/sdb1, so that a backup administrator can also unlock the volume, without removing or changing the original passphrase. Which command should the technician run?
- Acryptsetup luksChangeKey /dev/sdb1
- Bcryptsetup luksDump /dev/sdb1
- Ccryptsetup luksFormat /dev/sdb1
- Dcryptsetup luksAddKey /dev/sdb1
Show answer & explanationAnswer & explanation
Correct answer: D. cryptsetup luksAddKey /dev/sdb1
luksAddKey adds a new passphrase to an available key slot on a LUKS volume, keeping existing passphrases intact (LUKS supports up to 8 key slots in LUKS1, more in LUKS2). luksChangeKey replaces an existing key, luksFormat would destroy existing data by reinitializing the volume, and luksDump only displays header/key slot information.
Why the other options are wrong
- A. luksChangeKey replaces an existing passphrase in a slot rather than adding a new one alongside it.
- B. luksDump only displays header and key slot metadata; it does not add a key.
- C. luksFormat initializes a new LUKS header, destroying any existing encrypted data and keys.
LUKS Multi-User Key Management
LUKS supports multiple key slots, allowing several independent passphrases (or keyfiles) to unlock the same encrypted volume; cryptsetup luksAddKey adds a new one without disturbing existing keys.
- LUKS1 supports 8 key slots; LUKS2 supports up to 32
- luksAddKey requires an existing valid passphrase to authorize the add
- luksRemoveKey deletes a specific passphrase/key slot
- luksDump shows slot usage and status
Memory trick: 'AddKey' = adding a spare house key to the same lock, not replacing the original.