CompTIA Linux+ (XK0-006)TroubleshootingMedium

A user reports that they can't access a critical application's data files located at `/opt/app/data`. The administrator checks the permissions with `ls -l /opt/app` and sees the following output: ``` drwx------ 2 root root 4096 Apr 20 10:00 data ``` The application runs as the user `appuser` and is a member of the `appgroup` group. What is the most likely cause of the access denied error and how should it be resolved?

  1. AThe `data` directory has insufficient permissions for `appuser`. Add read and write permissions for the group with `chmod g+rw /opt/app/data`.
  2. BThe `data` directory has insufficient permissions for `appuser`. Change permissions to `rwxr-x---` with `chmod 750 /opt/app/data`.
  3. CThe `data` directory has insufficient permissions for `appuser`. Add execute permission for others with `chmod o+x /opt/app/data`.
  4. DThe `data` directory is owned by `root`. Change ownership to `appuser` with `chown appuser:appgroup /opt/app/data`.
Show answer & explanation

Correct answer: D. The `data` directory is owned by `root`. Change ownership to `appuser` with `chown appuser:appgroup /opt/app/data`.

The directory `/opt/app/data` is owned by `root:root` and has permissions `drwx------`. This means only the `root` user can read, write, and execute (access) its contents. Since the application runs as `appuser`, which is neither `root` nor in the `root` group, `appuser` has no permissions. Changing ownership to `appuser:appgroup` would grant `appuser` full access (due to `rwx` for owner) and allow `appgroup` to be granted permissions if needed in the future.

Why the other options are wrong

  • A. Adding `rw` for the group (`g+rw`) would still not help `appuser` because `appuser` is not the owner and `appgroup` is not the group owner. The current group owner is `root`.
  • B. Changing permissions to `750` (`rwxr-x---`) would grant `appuser` access if `appuser` were the owner, and `appgroup` read/execute if `appgroup` were the group owner. However, `root:root` ownership remains, so `appuser` would still be 'other' and have no permissions.
  • C. Adding execute permission for others (`o+x`) would only grant execute, not read/write, and is generally not the most secure or direct way to grant a specific user/group access when ownership is incorrect.

Linux File Ownership & Permissions

Linux file permissions are controlled by owner, group, and others, with read (r), write (w), and execute (x) rights. Ownership (user and group) dictates which set of permissions applies to a given user or process.

  • Each file/directory has an owner user and an owner group.
  • Permissions are `rwx` for owner, group, and others.
  • `chown` changes ownership, `chmod` changes permissions.

Memory trick: Owner, Group, Others: The Linux Permission Trio.

More Troubleshooting questions