CompTIA Linux+ (XK0-006)Services and User ManagementMedium

A system administrator needs to grant a specific user, `devuser`, read and write access to a directory `/data/shared_configs` that is owned by `root` and has default permissions `rwxr-x---` (750). The administrator wants to achieve this without changing the ownership or the existing group permissions for `developers`. Which command correctly uses Access Control Lists (ACLs) to grant `devuser` the necessary permissions?

  1. Asetfacl -m u:devuser:rw /data/shared_configs
  2. Bchmod u+rw /data/shared_configs
  3. Cchown devuser /data/shared_configs
  4. Dsetfacl -M u:devuser:rwx /data/shared_configs
Show answer & explanation

Correct answer: A. setfacl -m u:devuser:rw /data/shared_configs

The `setfacl` command is used to set ACLs. The `-m` option is for 'modify' an ACL entry. `u:devuser:rw` specifies that the user `devuser` should have read and write permissions. This changes only the ACL for `devuser` without affecting the owner or group permissions.

Why the other options are wrong

  • B. `chmod u+rw` would only modify the owner's permissions, not grant specific permissions to another user without changing ownership.
  • C. `chown devuser` would change the ownership of the directory to `devuser`, which is explicitly stated as not desired.
  • D. The `-M` option is for modifying ACLs from a file, not directly from the command line. Also, `rwx` is more than the requested `rw`.

Setting ACLs for Specific Users

Access Control Lists (ACLs) allow granular permission management beyond traditional `rwx` bits. `setfacl -m u:<user>:<permissions> <file>` grants specific permissions to a user.

  • ACLs override or supplement traditional `rwx` permissions.
  • `setfacl -m` modifies an existing ACL or adds a new one.
  • `u:` prefix specifies a user, `g:` for a group.

Memory trick: Permissions are 'R'ead, 'W'rite, 'X'ecute, 'A'CLs are 'M'ore.

More Services and User Management questions