You must be able to create, modify and delete users and groups, set password aging with chage or passwd, and control login defaults like umask. The key skill is knowing which file or command flag actually takes effect last for a given user.
Start practicing
User and Group Management — choose a session length
Free · No account required
Domain overview
This domain covers local account and group administration on Linux: creating, modifying and deleting users and groups, password aging, the user private group scheme, and login-time defaults such as umask and shell configuration files. LFCS tests it through scenario questions where you pick the correct command, flags, or file to satisfy a stated policy.
Exam objectives
useradd, usermod, userdel and their flags for home directories, shells and supplementary groups
passwd -e, chage and /etc/shadow fields for password expiry and forced change
groupadd, groupmod, gpasswd and /etc/group, /etc/gshadow membership management
umask, /etc/profile, /etc/login.defs and per-user shell startup file precedence
Using userdel without -r leaves the home directory and mail spool behind, failing the requirement to remove them.
Editing /etc/profile for umask when a later-read per-user file such as ~/.bashrc overrides it, so the value stays 022.
Setting expiry with usermod -e (account expiry) instead of chage/passwd -e, which controls password expiry, not the account.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator wants to enforce that users in the 'contractors' group must change their password every 30 days, with a warning 7 days before expiry. Which command should be used?
2Which THREE commands can be used to list all users currently logged into the system?
3Which THREE files are directly related to user and group management in a Linux system? (Select three.)
4A user 'alice' cannot log in via SSH. The administrator checks /etc/passwd and sees: alice:x:1002:1002::/home/alice:/sbin/nologin. Which command should be used to allow alice to log in with a bash shell?
5A security policy requires that user 'svc_backup' have a password that never expires. Additionally, the account should be locked after 90 days of inactivity. Which set of commands achieves this?
6A user named 'charlie' has just been added to the 'devops' group. However, when 'charlie' runs 'sudo -l', no sudo entries are shown. What is the most likely cause?
7Scenario: You are managing a Linux server that hosts a web application. The application runs under the user 'webapp' and the group 'webgroup'. Recently, a new intern 'john' (username 'john') needs to be able to view and modify files in /var/www/html, which is owned by root:webgroup with permissions 775. John is currently a member of the group 'staff', but not 'webgroup'. The security policy requires that John must be able to edit files without using sudo, and his primary group must remain 'staff'. Which of the following actions should you take to meet the requirements?
8Arrange the steps to configure a new user account with sudo privileges on a Linux system.
9Order the steps to create a systemd service unit that runs a script at boot.
10Order the steps to set up passwordless SSH key-based authentication.
11Match each Linux boot component to its description.
12A security policy requires that a user's password must expire 90 days after last change, and the user must change it immediately on next login. The last password change was 30 days ago. Which set of commands achieves this?
13Existing user 'jdoe' is a member of groups 'users' (primary) and 'staff'. The administrator needs to add 'jdoe' to group 'projectx' while preserving existing supplementary group memberships. Which command achieves this?
14An administrator needs to delete user 'obsolete' and remove its home directory and mail spool. Which command should be used?
15A company follows the principle of least privilege. Several developers need sudo access to run specific commands like systemctl and journalctl. What is the best practice for granting this access?
16Which THREE fields are part of a standard /etc/group entry?
17A security policy requires that a user account 'temp_audit' be locked immediately without changing the password. Which command locks the account and prevents login?
18An administrator wants to force a user to change their password at next login. Which command should be used?
19A large company needs to create 100 user accounts from a list of names in a CSV file. Which tool is most efficient for batch user creation?
20A user reports that they cannot execute a file even though they are in the file's group. The file has permissions 644 and group ownership 'staff'. The user is a member of 'staff'. What is the likely issue?
21A temporary contractor 'contractor1' has left the company. The administrator needs to remove the user account and all associated files in the home directory. Which command accomplishes this?
22An administrator needs to view a list of users who have logged in recently. Which command provides this information?
23Which two commands can be used to set password expiration policies for a user?
24Which two commands can add an existing user to a supplementary group?
25Refer to the exhibit. The administrator attempted to create a user 'newuser' but received an error. Which command should be used to check if the user already exists?
26A junior administrator issued the command 'usermod -L alice' to lock the account of user alice. However, alice is still able to log in via SSH using a public key. What is the most likely reason?
27A system administrator needs to create a shared group 'projectx' and add existing users 'bob' and 'carol' to it. The users need to collaborate on files in a directory /projectx. What is the correct sequence of commands to set up the group and ensure new files created in /projectx are automatically owned by the group 'projectx'?
28A security policy requires that all users in the 'admin' group must have a umask of 027 set automatically upon login. An administrator adds 'umask 027' to /etc/profile. However, users report that the umask is still 022. What is a likely cause?
29An administrator wants to change the primary group of user 'jane' from 'staff' to 'developers'. Which command accomplishes this?
30Which command will display all groups a specific user belongs to, including both primary and supplementary groups?
31Which TWO commands can be used to display the group membership of a user? (Choose two.)
32Which command adds an existing user to a supplementary group without removing the user from other groups?
33A user must change their password at next login per security policy. The admin wants to expire the password immediately. Which command accomplishes this?
34After deleting user 'alice', the system administrator wants to also remove the home directory and mail spool. Which command should be used?
35Which file stores the encrypted password (or password hash) for user accounts?
36Which THREE of the following statements about the user private group (UPG) scheme are true?
37You are managing a Linux server that hosts a shared project directory /projects/alpha, owned by the group 'alpha' (GID 2001). The directory has permissions 2770 (setgid, rwx for owner and group, no access for others). User 'jane' (UID 1501) has a primary group 'staff' (GID 1001) and is not in the 'alpha' group. She reports being unable to list or modify files in /projects/alpha. You need to give her access as a member of the 'alpha' group without changing her primary group. Which command sequence should you use?
38A Linux server hosts a shared project workspace at /srv/design. The directory is owned by root and currently has permissions 0775 with group ownership set to the 'designers' group. A new file was just created inside /srv/design by user 'mira' (a member of designers), and the file's group is showing as 'mira' instead of 'designers'. The team lead wants every NEW file and subdirectory created under /srv/design to automatically inherit the 'designers' group, while leaving existing files untouched. Which command should the administrator run?
39An administrator is auditing a server and needs to list only the users whose primary group is 'developers'. The system has many users, and the administrator wants a precise, scriptable one-liner that parses /etc/passwd. Which command accomplishes this?
40A junior administrator needs to add user 'mchen' to the supplementary group 'developers' without removing existing group memberships. Which command should be used?
41A junior administrator created a user account with the command `useradd -m devuser`. The account was created without a password, and the administrator now wants to set an initial password so the user can log in. Which command should the administrator use to assign a password to the account?
42A user 'dlee' reports that they cannot run 'sudo' commands despite being in the 'wheel' group. The /etc/sudoers file contains the line '%wheel ALL=(ALL) ALL'. What is the most likely cause?
You must be able to create, modify and delete users and groups, set password aging with chage or passwd, and control login defaults like umask. The key skill is knowing which file or command flag actually takes effect last for a given user.
The Courseiva LFCS question bank contains 42 questions in the User and Group Management domain, covering the 10% of the exam attributed to this domain in the official Linux Foundation blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the User and Group Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included