CompTIA Linux+ (XK0-006)System ManagementHard

A technician needs to encrypt a new partition /dev/sdb1 using LUKS before creating a filesystem on it. Which sequence of commands correctly encrypts the partition, opens it for use, and creates an ext4 filesystem on the mapped device?

  1. Acryptsetup luksOpen /dev/sdb1 secure_vol; cryptsetup luksFormat /dev/sdb1; mkfs.ext4 /dev/sdb1
  2. Bmkfs.ext4 /dev/sdb1; cryptsetup luksFormat /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol
  3. Ccryptsetup luksFormat /dev/mapper/secure_vol; mkfs.ext4 /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol
  4. Dcryptsetup luksFormat /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol
Show answer & explanation

Correct answer: D. cryptsetup luksFormat /dev/sdb1; cryptsetup luksOpen /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol

The correct order is: format the raw partition with a LUKS header (luksFormat), open it to create a decrypted mapped device (luksOpen), then build the filesystem on the mapper device. Formatting the filesystem before encryption or opening before a LUKS header exists will fail or destroy data.

Why the other options are wrong

  • A. Attempts to open a device before it has been LUKS-formatted, which will fail.
  • B. Creates a filesystem before encrypting, which the encryption step would destroy.
  • C. References the mapper device before it exists, which is invalid.

LUKS Encryption Workflow

LUKS encrypts a block device; the standard process formats the raw device, opens it to a mapped name, then filesystem operations occur on /dev/mapper/<name>.

  • luksFormat writes LUKS header to raw partition
  • luksOpen creates /dev/mapper/<name> decrypted device
  • Filesystem is created on the mapper device, not raw partition
  • luksClose closes the mapped device when done

Memory trick: Format, Open, then Format the Filesystem

More System Management questions