CompTIA Linux+ (XK0-006)SecurityHard

A technician must encrypt an entire new data partition, /dev/sdb1, using LUKS full-disk encryption, then mount it for use with a mapped device name of secure_vol. Which sequence of commands is correct?

  1. Amkfs.ext4 /dev/sdb1; cryptsetup luksFormat /dev/sdb1; mount /dev/sdb1 /mnt/secure
  2. Bcryptsetup open /dev/sdb1 secure_vol; cryptsetup luksFormat /dev/sdb1; mount /dev/mapper/secure_vol /mnt/secure
  3. Ccryptsetup luksFormat /dev/sdb1; mount /dev/sdb1 /mnt/secure
  4. Dcryptsetup luksFormat /dev/sdb1; cryptsetup open /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol; mount /dev/mapper/secure_vol /mnt/secure
Show answer & explanation

Correct answer: D. cryptsetup luksFormat /dev/sdb1; cryptsetup open /dev/sdb1 secure_vol; mkfs.ext4 /dev/mapper/secure_vol; mount /dev/mapper/secure_vol /mnt/secure

The correct LUKS workflow is: format the raw partition with luksFormat to establish encryption, open it to create the decrypted mapped device (/dev/mapper/secure_vol), create a filesystem on the now-accessible mapped device, and finally mount that mapped device. Options B, C, and D perform steps out of order or skip required steps.

Why the other options are wrong

  • A. Creating a filesystem before encrypting the raw device is pointless since luksFormat destroys any existing filesystem.
  • B. You cannot open a LUKS device with cryptsetup open before it has actually been formatted with luksFormat.
  • C. You cannot mount a raw LUKS-formatted block device directly; it must first be opened and have a filesystem created.

LUKS Encryption Workflow

LUKS (Linux Unified Key Setup) encrypts block devices; the standard workflow is format, open (unlock to mapper device), create filesystem, then mount.

  • cryptsetup luksFormat initializes encryption on the raw device
  • cryptsetup open creates a decrypted device at /dev/mapper/<name>
  • Filesystem is created on the mapper device, not the raw device
  • cryptsetup close unmounts the mapping when done

Memory trick: Format the safe, Open the safe, Furnish the safe, Mount the door.

More Security questions