CompTIA Linux+ (XK0-006)SecurityMedium

A technician needs to add a second passphrase to an already-encrypted LUKS partition, /dev/sdb1, so that a backup administrator can also unlock the volume, without removing or changing the original passphrase. Which command should the technician run?

  1. Acryptsetup luksChangeKey /dev/sdb1
  2. Bcryptsetup luksDump /dev/sdb1
  3. Ccryptsetup luksFormat /dev/sdb1
  4. Dcryptsetup luksAddKey /dev/sdb1
Show answer & explanation

Correct answer: D. cryptsetup luksAddKey /dev/sdb1

luksAddKey adds a new passphrase to an available key slot on a LUKS volume, keeping existing passphrases intact (LUKS supports up to 8 key slots in LUKS1, more in LUKS2). luksChangeKey replaces an existing key, luksFormat would destroy existing data by reinitializing the volume, and luksDump only displays header/key slot information.

Why the other options are wrong

  • A. luksChangeKey replaces an existing passphrase in a slot rather than adding a new one alongside it.
  • B. luksDump only displays header and key slot metadata; it does not add a key.
  • C. luksFormat initializes a new LUKS header, destroying any existing encrypted data and keys.

LUKS Multi-User Key Management

LUKS supports multiple key slots, allowing several independent passphrases (or keyfiles) to unlock the same encrypted volume; cryptsetup luksAddKey adds a new one without disturbing existing keys.

  • LUKS1 supports 8 key slots; LUKS2 supports up to 32
  • luksAddKey requires an existing valid passphrase to authorize the add
  • luksRemoveKey deletes a specific passphrase/key slot
  • luksDump shows slot usage and status

Memory trick: 'AddKey' = adding a spare house key to the same lock, not replacing the original.

More Security questions