CompTIA Linux+ XK0-006 (V8) Practice Question

During a security audit, a vulnerability scanner reports that your servers are running OpenSSH 8.4p1, which it flags as vulnerable because the upstream project fixed CVE-2025-12345 in OpenSSH 9.7p1. The distribution vendor has released an updated package named openssh-8.4p1-6.el9 that it states resolves the CVE without changing the upstream version number. Which explanation best describes the vendor's patching approach and why the package is still considered compliant?

  • The vendor has backported the security patches into the 8.4p1 source, preserving API/ABI stability while the new package release tag (-6.el9) indicates the fix.

  • The vendor performed a rolling upgrade that replaced OpenSSH 8.4p1 with 9.7p1 but kept the old version string to avoid script breakage.

  • The vendor is fast-tracking the patch, so the vulnerability will only be removed when the servers are upgraded to OpenSSH 9.7p1 in the next major distribution release.

  • The vendor applied a live binary hot-patch directly to /usr/bin/sshd outside the package manager, so scanners cannot detect the new code.

CompTIA Linux+ XK0-006 (V8)
Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot