CompTIA Linux+ (XK0-006)SecurityHard

A security engineer configuring PAM on a Linux server needs to understand the order in which PAM management groups are typically processed for a login attempt. Which group is responsible for verifying the user's identity, such as checking a password against a stored hash?

  1. Apassword
  2. Bauth
  3. Caccount
  4. Dsession
Show answer & explanation

Correct answer: B. auth

The 'auth' management group in PAM handles authentication—verifying that the user is who they claim to be, typically by checking a supplied password or token against stored credentials. The other groups handle different stages: account (authorization/account status checks), password (updating credentials), and session (setup/teardown of the user session).

Why the other options are wrong

  • A. password handles updating authentication tokens (e.g., changing passwords), not initial verification.
  • C. account checks things like account expiration or time restrictions, not identity verification.
  • D. session manages tasks performed at the start/end of a session, such as mounting home directories or logging.

PAM Management Groups

PAM organizes rules into four management groups—auth, account, password, and session—each handling a distinct phase of the authentication and authorization process.

  • auth: verifies identity/credentials
  • account: checks account validity (expiration, time-of-day)
  • password: manages credential updates
  • session: handles setup/cleanup tasks around login

Memory trick: AAPS: Auth checks WHO you are, Account checks if you're ALLOWED, Password updates secrets, Session wraps the visit.

More Security questions