An administrator is analyzing a Linux server which was recently hacked. Which of the following will the administrator use to find all unsuccessful login attempts?
A classical Comptia question. faillock is in the exam objectives but in official book there is nothing about it. Only pam_faillock, so I choose pam_tally2.
nakres64 you're 100% correct. I read both the Pearson & McGraw Hill books and the Pearson book only mentions PAMs yet the McGraw Hill book tells you a bit about PAMs but covers pam_tally2 enough for me to confirm you are correct and that the answer is pam_tally2
This question is also in the official Comptia Study Guide, however in the Study Guide, the questions asks you to "choose two" . The back of the book then lists faillock and pamtally2 as the correct answers.
There are two PAM modules you can use to trigger a temporary user lockout if multiple
authentication attempts fail: pam_tally2 and pam_faillock. The
pam_faillock module is recommended, as it is a newer module that improves
upon pam_tally2 by supporting user lockout when authentication is done over a
screen saver.
Both tally and faillock do the same thing. Comptia's Student Guide recommends using faillock over tally2 because it's newere.
That being said if you consider it should be pam_faillock maybe than tally2 is the right answer
C. "To measure the number of failed logins per user, a module is needed to do the counting. Two popular modules for this are pam_tally and pam_tally2, named after tallying"
https://linux-audit.com/locking-users-after-failed-login-attempts-with-pam_tally2/
Correct answer is pam_tally2 as it shows failed login attempts for all users. faillock seems to only be used for a single user.
upvoted 3 times
...
...
...
This section is not available anymore. Please use the main Exam Page.XK0-004 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
nakres64
Highly Voted 4 years, 3 months agoIcarus1987
4 years, 2 months agojc0le
Highly Voted 4 years, 2 months agoc98ba22
Most Recent 7 months, 3 weeks agosargeholik
2 years, 8 months agopetercorn
3 years, 6 months agoBubu3k
4 years, 5 months agodave369
5 years agopinkcyberpenguin
5 years, 1 month agoMurderface84
5 years agoIcarus1987
4 years, 2 months ago