An X11-forwarded ssh session authorises the remote client to talk to your local X server without you ever running an xhost command. Which mechanism provides that authorisation?

LPIC-1 Exam 102-500, objective 106. User interfaces and desktops hard

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct The Xorg configuration file /etc/X11/xorg.conf, which lists permitted remote hosts.

Wrong. xorg.conf configures the server's hardware and layout — screens, input devices, monitors, drivers, modules. It holds no client authorisation list, and on modern systems it is often absent entirely because Xorg autodetects.

Not correct The user's ~/.Xresources file, read at session start.

Wrong. ~/.Xresources holds X resource defaults for client appearance and behaviour, such as XTerm*background. It is loaded into the server's resource database with xrdb and has nothing to do with access control.

Not correct The DISPLAY variable itself, whose value doubles as a shared secret.

Wrong. DISPLAY is only an address telling the client where the server is. It carries no secret and is routinely visible in the environment of every process.

Correct A per-display authorisation cookie stored in the user's ~/.Xauthority file and managed with xauth.

Correct. X uses MIT-MAGIC-COOKIE-1 tokens kept in ~/.Xauthority. ssh generates a cookie for the proxy display on the remote host and writes it into the remote user's Xauthority file, so the forwarded client can authenticate to your local server.

Why

There are two families of X access control. Host-based control with xhost trusts an entire machine and is coarse and unsafe. Cookie-based control is per-user and per-display: a random token lives in ~/.Xauthority, and a client must present it. `xauth list` shows the stored entries, `xauth extract`/`xauth merge` move them between hosts, and `xauth remove` deletes one. If ~/.Xauthority is unwritable or removed, forwarded sessions typically fail with "cannot open display".

Where this comes from

Cited
LPI exam objective 106.1
What it says
Awareness of X authorisation using xhost, xauth and the .Xauthority file.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 106 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500