Which steps enable LUKS encryption on a USB device?

A systems administrator is enabling LUKS on a USB storage device with an ext4 filesystem format. The administrator runs dmesg and notices the following output: Given this scenario, which of the following should the administrator perform to meet these requirements? (Choose three.) - image

  1. gpg /dev/sdc1
  2. pvcreate /dev/sdc Source Reference Answer
  3. mkfs.ext4 /dev/mapper/LUKS0001 - L ENCRYPTED Source Reference Answer
  4. umount /dev/sdc
  5. fdisk /dev/sdc

Community Insight

The exam tests knowledge of the LUKS encryption workflow on Linux, with the common trap being confusion between partitioning, LVM, and LUKS commands.

This question tests the correct sequence of commands to enable LUKS encryption on a USB storage device and format it with ext4. Community consensus highlights the need to unmount the device, initialize LUKS, and format the mapped device.

Many candidates incorrectly select pvcreate (B) or mkfs.ext4 with invalid syntax (C), misunderstanding that LUKS requires cryptsetup and proper device mapping before formatting.

Community Discussion (3 comments)

HappyDay030303 👍 1 Selected: DE
D. umount /dev/sdc The filesystem is currently mounted (as seen in the dmesg output), and you cannot encrypt a mounted partition. You must unmount the device before formatting or encrypting it. E. fdisk /dev/sdc You may need to delete existing partitions and create a new one (like /dev/sdc1) to prepare the disk for encryption and new formatting. fdisk helps manage the partition table H. cryptsetup luksFormat /dev/sdc1 This command initializes the partition with LUKS encryption It formats the partition for encrypted use (you’ll need to confirm and enter a passphrase)
Kashim 👍 4 Selected: BC
H. cryptsetup luksFormat /dev/sdc1 This command initializes the LUKS partition on /dev/sdc1, preparing it for encryption. B. pvcreate /dev/sdc This command initializes a physical volume for use by LVM, which might be used after the LUKS setup. C. mkfs.ext4 /dev/mapper/LUKS0001 - L ENCRYPTED After setting up LUKS and mapping it, this command formats the LUKS-encrypted device with the ext4 filesystem.
IFBBPROSALCEDO 👍 2 Selected: D
Given the scenario where a systems administrator is enabling LUKS (Linux Unified Key Setup) on a USB storage device with an ext4 filesystem format, the following steps should be performed: 1. Unmount the USB storage device to ensure that it is not in use. This is necessary to modify the filesystem. - D. umount /dev/sdc 2. Initialize LUKS on the USB storage device to set up encryption. - H. cryptsetup luksFormat /dev/sdc1 3. Create the filesystem on the LUKS encrypted device. Since the requirement is to have an ext4 filesystem, use mkfs.ext4. - C. mkfs.ext4 /dev/mapper/LUKS0001 -L ENCRYPTED Thus, the correct steps are: - D. umount /dev/sdc - H. cryptsetup luksFormat /dev/sdc1 - C. mkfs.ext4 /dev/mapper/LUKS0001 -L ENCRYPTED

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct steps involve unmounting the device (D), initializing LUKS with cryptsetup (not listed but implied), and formatting the mapped device with mkfs.ext4. The suggested answer (BC) is flawed because pvcreate is for LVM, not LUKS, and the mkfs.ext4 syntax is incorrect. Community comments correctly identify that unmounting is essential before encryption.

Why the Other Options Are Wrong

Option A (gpg) is unrelated to disk encryption. Option B (pvcreate) initializes LVM physical volumes, not LUKS. Option C uses invalid syntax for mkfs.ext4. Option E (fdisk) may be needed for partitioning but is not part of the LUKS setup itself.

Community Comment Notes

Comment [2] correctly emphasizes unmounting the device first, while comment [3] notes the potential need for fdisk to prepare partitions. Comment [1] mistakenly includes pvcreate and incorrect mkfs syntax, reflecting common misunderstandings about LUKS workflows.

Official Reference

Exam Strategy

Always verify the exact syntax and purpose of each command in the options. For LUKS-related questions, focus on cryptsetup, unmounting, and proper device mapping, and eliminate unrelated commands like gpg or pvcreate.

Related Analysis

← Back to XK0-005 Study Guide