CompTIA Linux+ (XK0-006)System ManagementHard
A technician needs to encrypt a new partition /dev/sdb1 using LUKS before creating a filesystem on it. Which sequence of commands correctly encrypts the partition, opens it for use, and creates an ext4 filesystem on the mapped device?
- Acryptsetup luksOpen /dev/sdb1 secure_vol; cryptsetup luksFormat /dev/sdb1; mkfs.ext4 /dev/sdb1
- Bmkfs.ext4 /dev/sdb1; cryptsetup luksFormat /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol
- Ccryptsetup luksFormat /dev/mapper/secure_vol; mkfs.ext4 /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol
- Dcryptsetup luksFormat /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol
Show answer & explanationAnswer & explanation
Correct answer: D. cryptsetup luksFormat /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol
The correct order is: format the raw partition with a LUKS header (luksFormat), open it to create a decrypted mapped device (luksOpen), then build the filesystem on the mapper device. Formatting the filesystem before encryption or opening before a LUKS header exists will fail or destroy data.
Why the other options are wrong
- A. Attempts to open a device before it has been LUKS-formatted, which will fail.
- B. Creates a filesystem before encrypting, which the encryption step would destroy.
- C. References the mapper device before it exists, which is invalid.
LUKS Encryption Workflow
LUKS encrypts a block device; the standard process formats the raw device, opens it to a mapped name, then filesystem operations occur on /dev/mapper/<name>.
- luksFormat writes LUKS header to raw partition
- luksOpen creates /dev/mapper/<name> decrypted device
- Filesystem is created on the mapper device, not raw partition
- luksClose closes the mapped device when done
Memory trick: Format, Open, then Format the Filesystem