CompTIA Linux+ (XK0-006)Services and User ManagementMedium
A system administrator needs to restrict a user named `devuser` from accessing certain sensitive files in the `/var/log/secure` directory, even though the directory has global read permissions. The administrator wants to explicitly deny `devuser` read access to `/var/log/secure` without affecting other users or groups. Which command sequence using Access Control Lists (ACLs) would achieve this?
- Asudo setfacl -m u:devuser:rwx /var/log/secure && sudo setfacl -d u:devuser:rwx /var/log/secure
- Bsudo setfacl -m u:devuser:r-- /var/log/secure
- Csudo setfacl -m u:devuser:--- /var/log/secure
- Dsudo setfacl -x u:devuser /var/log/secure
Show answer & explanationAnswer & explanation
Correct answer: C. sudo setfacl -m u:devuser:--- /var/log/secure
The `setfacl -m` command is used to modify ACLs. `u:devuser:---` explicitly sets no permissions (read, write, execute) for the user `devuser`. This effectively denies access, overriding any broader directory permissions.
Why the other options are wrong
- A. This attempts to grant `rwx` and then set default `rwx`, which does not deny access.
- B. This would grant `devuser` read-only access, which is the opposite of the requirement to deny access.
- D. The `-x` option is used to remove an ACL entry, not to set one.
ACL (Access Control List)
ACLs provide a more granular way to manage file system permissions than traditional Unix permissions, allowing specific permissions for individual users or groups.
- Managed with `setfacl` (set) and `getfacl` (get) commands.
- Can explicitly grant or deny permissions beyond owner/group/other.
- Often used in conjunction with traditional permissions.
Memory trick: ACLs are like VIP lists for file access.