CompTIA Linux+ (XK0-006)SecurityHard
A technician must encrypt an entire new data partition, /dev/sdb1, using LUKS full-disk encryption, then mount it for use with a mapped device name of secure_vol. Which sequence of commands is correct?
- Amkfs.ext4 /dev/sdb1; cryptsetup luksFormat /dev/sdb1; mount /dev/sdb1 /mnt/secure
- Bcryptsetup open /dev/sdb1 secure_vol; cryptsetup luksFormat /dev/sdb1; mount /dev/mapper/secure_vol /mnt/secure
- Ccryptsetup luksFormat /dev/sdb1; mount /dev/sdb1 /mnt/secure
- Dcryptsetup luksFormat /dev/sdb1; cryptsetup open /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol; mount /dev/mapper/secure_vol /mnt/secure
Show answer & explanationAnswer & explanation
Correct answer: D. cryptsetup luksFormat /dev/sdb1; cryptsetup open /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol; mount /dev/mapper/secure_vol /mnt/secure
The correct LUKS workflow is: format the raw partition with luksFormat to establish encryption, open it to create the decrypted mapped device (/dev/mapper/secure_vol), create a filesystem on the now-accessible mapped device, and finally mount that mapped device. Options B, C, and D perform steps out of order or skip required steps.
Why the other options are wrong
- A. Creating a filesystem before encrypting the raw device is pointless since luksFormat destroys any existing filesystem.
- B. You cannot open a LUKS device with cryptsetup open before it has actually been formatted with luksFormat.
- C. You cannot mount a raw LUKS-formatted block device directly; it must first be opened and have a filesystem created.
LUKS Encryption Workflow
LUKS (Linux Unified Key Setup) encrypts block devices; the standard workflow is format, open (unlock to mapper device), create filesystem, then mount.
- cryptsetup luksFormat initializes encryption on the raw device
- cryptsetup open creates a decrypted device at /dev/mapper/<name>
- Filesystem is created on the mapper device, not the raw device
- cryptsetup close unmounts the mapping when done
Memory trick: Format the safe, Open the safe, Furnish the safe, Mount the door.