Be able to add and modify local users and groups, append supplementary groups with usermod -aG, configure password aging via chage, and confirm effective membership with id or groups. The critical detail: always use -a with -G, and re-login for group changes to apply.
Start practicing
Manage users and groups — choose a session length
Free · No account required
Domain overview
This domain covers local account and group administration on RHEL using useradd, usermod, groupadd, passwd, chage, and the /etc/passwd, /etc/shadow, and /etc/group files. Questions are hands-on: you add users, set supplementary groups, manage password aging, and verify effective group membership after re-login.
Exam objectives
Using usermod -aG to append supplementary groups without dropping existing ones
Editing /etc/shadow fields with chage for password aging and inactivity lockout
Verifying effective group membership with the id and groups commands
Creating users and groups with useradd, groupadd, and setting passwords with passwd
Running usermod -G without -a, which replaces all existing supplementary groups instead of appending the new ones.
Assuming group changes apply to the current session; membership only takes effect after logout and login.
Confusing the /etc/shadow inactivity field with account expiration, or miscounting the colon-separated fields.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A system administrator needs to ensure that a user named 'bob' can access a shared directory '/data' owned by group 'developers'. The directory has permissions 2775 and is owned by root:developers. Bob is a member of the 'developers' group. However, when Bob tries to create a file in '/data', it fails with 'Permission denied'. What is the most likely cause?
2A company policy requires that when a user is deleted, all files owned by that user in /home should be reassigned to a 'guest' account. Which command accomplishes this?
3An administrator wants to add the user 'jane' to the supplementary groups 'wheel' and 'docker' without removing her from other groups. Which command should be used?
4A server has a requirement that all users in the 'finance' group must have a password aging policy that forces password change every 90 days. Which approach best achieves this for existing users?
5Which TWO commands can change the primary group of an existing user?
6A system administrator needs to ensure that the user 'jdoe' cannot log in via SSH but can still use other services like FTP. Which approach should the administrator take?
7Arrange the steps to configure a network bond (mode 1) using two interfaces (eth0, eth1) in RHEL.
8Match each firewall zone to its default trust level.
9A company needs to create a user account for a temporary contractor who will work for exactly 90 days. The account must be automatically disabled after 90 days. Which command should the administrator use?
10A user named jdoe is receiving 'Permission denied' errors when trying to access a file owned by root with permissions 644. The user is a member of the root group. What is the most likely cause?
11After being added to a new supplementary group with usermod -aG, a user logs out and back in but still cannot access files owned by that group. Which command should the user run to verify current effective group membership?
12A new employee named asmith needs a user account with a home directory and a specific UID of 1500. Which command accomplishes this?
13A system administrator needs to change the primary group of an existing user to a group that already exists. Which command should be used?
14A server has been compromised, and the administrator suspects an unauthorized user account may have been created. Which file should be examined to list all local user accounts?
15An administrator wants to ensure that any new user accounts created on the system have a default primary group matching the username. What change is needed?
16An administrator used the command useradd -D -f 10 to change the default inactivity period. What effect does this have on future user accounts?
17Which TWO commands can be used to add a user to a secondary group without removing existing supplementary group memberships? (Choose exactly 2)
18Which THREE statements about /etc/shadow are true? (Choose exactly 3)
19Which TWO commands can list all groups a user belongs to? (Choose exactly 2)
20Refer to the exhibit. A user named 'carol' has been added to the system with the command useradd -G wheel carol. Which line in /etc/group will confirm that carol is now a member of the wheel group?
21Refer to the exhibit. What effect does the value INACTIVE=-1 have on newly created user accounts?
22A system administrator needs to ensure that a user named 'jdoe' can execute commands as root without being prompted for a password. Which configuration change should be made?
23A user reports they cannot log in to a Linux system. Their account was recently created. The administrator checks /etc/passwd and sees the entry: jsmith:x:1001:1001::/home/jsmith:/sbin/nologin. What is the likely issue?
24An administrator is migrating user accounts to a new system. They want to preserve the user's primary group name and GID. Which commands should be used in sequence?
25A helpdesk ticket states that user 'bob' cannot write to his own home directory. The directory /home/bob has permissions drwxr-xr-x and is owned by root:root. What command will fix this?
26An administrator needs to create a user account that will be used by an application service. The account should not have a valid shell or home directory. Which command correctly creates such an account?
27An administrator wants to modify the default expiration settings for new user passwords. Which file should be modified?
28An administrator accidentally deleted the group 'sales' which is the primary group of several users. What is the immediate effect on those users?
29Which TWO commands can be used to add a user to an existing supplementary group without removing them from other groups?
30A user jdoe, who is a member of the group staff, reports they cannot access the directory /shared. The administrator runs getfacl /shared and receives the output shown. Which of the following explains the issue?
31Alice tries to run 'sudo less /var/log/messages' and gets 'Sorry, user alice is not allowed to execute /usr/bin/less /var/log/messages as root on this host.' Why?
32A system administrator needs to ensure that the user 'jdoe' can read files in the shared directory /project/data which is owned by group 'project'. The user 'jdoe' is currently not a member of the 'project' group. Which TWO steps should the administrator take to add 'jdoe' to the 'project' group? (Choose two.)
33A Red Hat Enterprise Linux 9 system enforces a security policy that user accounts must be disabled after 90 days of inactivity. The system administrator has configured /etc/shadow accordingly with the proper fields. User 'bob' has been on leave for 95 days. When bob returns and tries to log in, he is unable to do so. The administrator checks the shadow file and sees that bob's password expiration date has passed and the account is locked due to inactivity (the inactivity period has exceeded). The administrator wants to immediately reactivate bob's account without changing the password, and also wants to set the account to expire in 30 days from now (relative to the current date). Which set of commands should the administrator run to achieve this goal?
34Which TWO commands can be used to create a new user account in Red Hat Enterprise Linux 8?
35A user was recently added to the 'testgrp' group using `usermod -aG testgrp user1`. However, when they try to access a file owned by testgrp with permissions 660, they get permission denied. What is the most likely reason?
36You are managing a Red Hat Enterprise Linux 8 server that hosts backup scripts. A user named 'backup' (UID 1005) is a member of the 'backup' group. The directory /var/backups is owned by root:backup with permissions 775. The 'backup' user needs to create files in this directory. However, when the user attempts to create a file, they receive 'Permission denied'. You verify that 'backup' is indeed listed in the backup group in /etc/group. The user's current shell was started after their last login. Which of the following is the most likely cause and solution?
37A junior administrator is asked to create a new group named 'qa' with an explicit GID of 4500 on a Red Hat Enterprise Linux 8 server. After running the appropriate command, they verify the result with getent group qa and see 'qa:x:4500:'. Which command did the junior administrator most likely run?
Be able to add and modify local users and groups, append supplementary groups with usermod -aG, configure password aging via chage, and confirm effective membership with id or groups. The critical detail: always use -a with -G, and re-login for group changes to apply.
The Courseiva EX200 question bank contains 37 questions in the Manage users and groups domain, covering the 11% of the exam attributed to this domain in the official Red Hat blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Manage users and groups domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included