CompTIA Linux+ (XK0-006)SecurityHard
A security engineer configuring PAM on a Linux server needs to understand the order in which PAM management groups are typically processed for a login attempt. Which group is responsible for verifying the user's identity, such as checking a password against a stored hash?
- Apassword
- Bauth
- Caccount
- Dsession
Show answer & explanationAnswer & explanation
Correct answer: B. auth
The 'auth' management group in PAM handles authentication—verifying that the user is who they claim to be, typically by checking a supplied password or token against stored credentials. The other groups handle different stages: account (authorization/account status checks), password (updating credentials), and session (setup/teardown of the user session).
Why the other options are wrong
- A. password handles updating authentication tokens (e.g., changing passwords), not initial verification.
- C. account checks things like account expiration or time restrictions, not identity verification.
- D. session manages tasks performed at the start/end of a session, such as mounting home directories or logging.
PAM Management Groups
PAM organizes rules into four management groups—auth, account, password, and session—each handling a distinct phase of the authentication and authorization process.
- auth: verifies identity/credentials
- account: checks account validity (expiration, time-of-day)
- password: manages credential updates
- session: handles setup/cleanup tasks around login
Memory trick: AAPS: Auth checks WHO you are, Account checks if you're ALLOWED, Password updates secrets, Session wraps the visit.