CompTIA Linux+ (XK0-006)SecurityMedium

A system administrator needs to ensure that all users on a Linux server are subject to a maximum of 3 failed login attempts before their account is locked out for 5 minutes. Which PAM configuration file should be modified to implement this policy for local user authentication?

  1. A/etc/pam.d/common-auth
  2. B/etc/pam.d/system-auth
  3. C/etc/pam.d/sshd
  4. D/etc/pam.d/login
Show answer & explanation

Correct answer: A. /etc/pam.d/common-auth

To apply a failed login attempt policy to all authentication services that use common PAM configurations, /etc/pam.d/common-auth is the most appropriate file. Modifying this file centrally impacts services linked to it, such as login and sshd, ensuring consistent policy enforcement.

Why the other options are wrong

  • B. /etc/pam.d/system-auth is another common include, but common-auth is often used for authentication-specific settings like 'auth' module types, which include faillock.
  • C. /etc/pam.d/sshd specifically targets SSH authentication and would not apply to other local login methods.
  • D. /etc/pam.d/login specifically targets console login and would not apply to other services like SSH.

PAM common-auth

The /etc/pam.d/common-auth file is a common PAM configuration file used to define authentication policies that apply to multiple services on a Linux system.

  • Often included by other service-specific PAM files (e.g., login, sshd).
  • Used for defining authentication-related modules like pam_unix.so or pam_faillock.so.
  • Modifying it provides a centralized way to enforce system-wide authentication policies.

Memory trick: PAM's Common Auth is like a central library for all login rules.

More Security questions