CompTIA Linux+ (XK0-006)SecurityHard

A company's compliance policy requires that any local account be automatically locked for 15 minutes after five consecutive failed login attempts. Which PAM configuration change correctly enforces this using pam_faillock on a modern RHEL-based system?

  1. AAdd 'auth sufficient pam_permit.so' to /etc/pam.d/login
  2. BSet 'deny=5 unlock_time=900' for pam_faillock in /etc/security/faillock.conf
  3. CAdd 'session required pam_limits.so' to /etc/pam.d/system-auth
  4. DSet 'minlen=5 maxrepeat=900' in /etc/security/pwquality.conf
Show answer & explanation

Correct answer: B. Set 'deny=5 unlock_time=900' for pam_faillock in /etc/security/faillock.conf

pam_faillock tracks failed login attempts and enforces lockouts; its deny and unlock_time parameters, configured in /etc/security/faillock.conf (or as module arguments in the PAM stack), define the failure threshold (5) and lockout duration in seconds (900 seconds = 15 minutes), exactly matching the requirement.

Why the other options are wrong

  • A. pam_permit.so unconditionally allows authentication and would weaken security rather than enforce lockouts.
  • C. pam_limits.so manages resource limits like file descriptors, not failed login lockouts.
  • D. pwquality.conf controls password complexity rules, not account lockout behavior; minlen/maxrepeat are unrelated to lockout timing.

pam_faillock Account Lockout

pam_faillock is a PAM module that locks user accounts after a configurable number of consecutive failed login attempts for a configurable duration, mitigating brute-force attacks.

  • deny=N sets the failed-attempt threshold
  • unlock_time=SECONDS sets automatic lockout duration (0 = permanent until admin unlock)
  • Configured in /etc/security/faillock.conf or inline in PAM files
  • faillock --user <name> shows and can reset a locked account

Memory trick: Five strikes, fifteen-minute penalty box — deny=5, unlock_time=900.

More Security questions