CompTIA Linux+ (XK0-006)Services and User ManagementMedium

A system administrator needs to restrict a user named `devuser` from accessing certain sensitive files in the `/var/log/secure` directory, even though the directory has global read permissions. The administrator wants to explicitly deny `devuser` read access to `/var/log/secure` without affecting other users or groups. Which command sequence using Access Control Lists (ACLs) would achieve this?

  1. Asudo setfacl -m u:devuser:rwx /var/log/secure && sudo setfacl -d u:devuser:rwx /var/log/secure
  2. Bsudo setfacl -m u:devuser:r-- /var/log/secure
  3. Csudo setfacl -m u:devuser:--- /var/log/secure
  4. Dsudo setfacl -x u:devuser /var/log/secure
Show answer & explanation

Correct answer: C. sudo setfacl -m u:devuser:--- /var/log/secure

The `setfacl -m` command is used to modify ACLs. `u:devuser:---` explicitly sets no permissions (read, write, execute) for the user `devuser`. This effectively denies access, overriding any broader directory permissions.

Why the other options are wrong

  • A. This attempts to grant `rwx` and then set default `rwx`, which does not deny access.
  • B. This would grant `devuser` read-only access, which is the opposite of the requirement to deny access.
  • D. The `-x` option is used to remove an ACL entry, not to set one.

ACL (Access Control List)

ACLs provide a more granular way to manage file system permissions than traditional Unix permissions, allowing specific permissions for individual users or groups.

  • Managed with `setfacl` (set) and `getfacl` (get) commands.
  • Can explicitly grant or deny permissions beyond owner/group/other.
  • Often used in conjunction with traditional permissions.

Memory trick: ACLs are like VIP lists for file access.

More Services and User Management questions