Which steps enable LUKS encryption on a USB device?
A systems administrator is enabling LUKS on a USB storage device with an ext4 filesystem format. The administrator runs dmesg and notices the following output: Given this scenario, which of the following should the administrator perform to meet these requirements? (Choose three.) - 
Community Insight
The exam tests knowledge of the LUKS encryption workflow on Linux, with the common trap being confusion between partitioning, LVM, and LUKS commands.
This question tests the correct sequence of commands to enable LUKS encryption on a USB storage device and format it with ext4. Community consensus highlights the need to unmount the device, initialize LUKS, and format the mapped device.
Many candidates incorrectly select pvcreate (B) or mkfs.ext4 with invalid syntax (C), misunderstanding that LUKS requires cryptsetup and proper device mapping before formatting.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct steps involve unmounting the device (D), initializing LUKS with cryptsetup (not listed but implied), and formatting the mapped device with mkfs.ext4. The suggested answer (BC) is flawed because pvcreate is for LVM, not LUKS, and the mkfs.ext4 syntax is incorrect. Community comments correctly identify that unmounting is essential before encryption.Why the Other Options Are Wrong
Option A (gpg) is unrelated to disk encryption. Option B (pvcreate) initializes LVM physical volumes, not LUKS. Option C uses invalid syntax for mkfs.ext4. Option E (fdisk) may be needed for partitioning but is not part of the LUKS setup itself.Community Comment Notes
Comment [2] correctly emphasizes unmounting the device first, while comment [3] notes the potential need for fdisk to prepare partitions. Comment [1] mistakenly includes pvcreate and incorrect mkfs syntax, reflecting common misunderstandings about LUKS workflows.Official Reference
Exam Strategy
Always verify the exact syntax and purpose of each command in the options. For LUKS-related questions, focus on cryptsetup, unmounting, and proper device mapping, and eliminate unrelated commands like gpg or pvcreate.
umount /dev/sdc2. Initialize LUKS on the USB storage device to set up encryption. - H.cryptsetup luksFormat /dev/sdc13. Create the filesystem on the LUKS encrypted device. Since the requirement is to have an ext4 filesystem, use mkfs.ext4. - C.mkfs.ext4 /dev/mapper/LUKS0001 -L ENCRYPTEDThus, the correct steps are: - D.umount /dev/sdc- H.cryptsetup luksFormat /dev/sdc1- C.mkfs.ext4 /dev/mapper/LUKS0001 -L ENCRYPTED