CompTIA Linux+ (XK0-006)SecurityHard
A company's compliance policy requires that any local account be automatically locked for 15 minutes after five consecutive failed login attempts. Which PAM configuration change correctly enforces this using pam_faillock on a modern RHEL-based system?
- AAdd 'auth sufficient pam_permit.so' to /etc/pam.d/login
- BSet 'deny=5 unlock_time=900' for pam_faillock in /etc/security/faillock.conf
- CAdd 'session required pam_limits.so' to /etc/pam.d/system-auth
- DSet 'minlen=5 maxrepeat=900' in /etc/security/pwquality.conf
Show answer & explanationAnswer & explanation
Correct answer: B. Set 'deny=5 unlock_time=900' for pam_faillock in /etc/security/faillock.conf
pam_faillock tracks failed login attempts and enforces lockouts; its deny and unlock_time parameters, configured in /etc/security/faillock.conf (or as module arguments in the PAM stack), define the failure threshold (5) and lockout duration in seconds (900 seconds = 15 minutes), exactly matching the requirement.
Why the other options are wrong
- A. pam_permit.so unconditionally allows authentication and would weaken security rather than enforce lockouts.
- C. pam_limits.so manages resource limits like file descriptors, not failed login lockouts.
- D. pwquality.conf controls password complexity rules, not account lockout behavior; minlen/maxrepeat are unrelated to lockout timing.
pam_faillock Account Lockout
pam_faillock is a PAM module that locks user accounts after a configurable number of consecutive failed login attempts for a configurable duration, mitigating brute-force attacks.
- deny=N sets the failed-attempt threshold
- unlock_time=SECONDS sets automatic lockout duration (0 = permanent until admin unlock)
- Configured in /etc/security/faillock.conf or inline in PAM files
- faillock --user <name> shows and can reset a locked account
Memory trick: Five strikes, fifteen-minute penalty box — deny=5, unlock_time=900.