hardMultiple Choice
220-1202 Practice Question: A system administrator needs to add a new user…
A system administrator needs to add a new user 'jdoe' to the system and ensure that their home directory is created with restrictive permissions so that no other users can access it. Which command sequence achieves this?
⚠ Common exam trap
CompTIA often tests the distinction between creating a user with default permissions versus explicitly setting restrictive permissions, and the trap here is that candidates may assume `useradd -m` alone or a group-based option (like `-g`) automatically enforces privacy, when in fact the umask or default settings can leave the home directory accessible to others.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
useradd -m jdoe && chmod 700 /home/jdoe
`useradd -m jdoe` creates the user and their home directory `/home/jdoe`, and `chmod 700 /home/jdoe` sets the directory permissions to `rwx------`, which grants full access only to the owner (jdoe) and denies all access to group and others. This meets the requirement of restrictive permissions so that no other users can access the home directory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
useradd -m jdoe && chmod 700 /home/jdoe
Why this is correct
The -m flag makes useradd create /home/jdoe, then chmod 700 strips all group and other permissions, leaving read, write and execute for the owner alone. This satisfies the requirement that no other users can access the home directory.
- ✗
useradd jdoe && chmod 755 /home/jdoe
Why it's wrong here
chmod 755 grants read and execute to group and others, so other users can traverse and read the home directory, contradicting the restrictive-permission requirement. It is tempting because 755 is the common default for home directories, and it would be acceptable where other users legitimately need read access.
- ✗
adduser jdoe --private
Why it's wrong here
adduser accepts no --private flag; the command fails with an invalid-option error, so no account or home directory is created. It is tempting because adduser is the friendly interactive wrapper that does create home directories, and it would be correct for routine interactive account creation without the permission requirement.
- ✗
useradd -m -g jdoe jdoe
Why it's wrong here
The -g flag assigns jdoe's primary group to an existing group named jdoe; it does not create the home directory or set its permissions. It is tempting because -m does create the home directory, but the stem also demands restrictive permissions that this sequence never applies.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.