Courseiva

XK0-006 Services and User Management Practice Question

A security policy mandates that user 'alice' must change her password every 60 days and must be warned 7 days before expiration. Which command should be used to enforce this?

⚠ Common exam trap

Test-takers frequently confuse the -m (minimum days) and -M (maximum days) options of chage, or assuming passwd supports the same aging flags on all distributions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

chage -M 60 -W 7 alice

The chage command directly manipulates the password aging fields in /etc/shadow. Using -M 60 enforces the maximum days a password is valid, and -W 7 provides a warning to the user seven days before expiration. This is the correct and portable method to comply with the stated security policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    passwd -x 60 -w 7 alice

    Why it's wrong here

    passwd -x sets the maximum password lifetime and -w sets the warning period, but these options are not available on all Linux distributions. On many systems, passwd does not support -x or -w; chage is the portable and standard tool for managing password aging information.

  • ✓

    chage -M 60 -W 7 alice

    Why this is correct

    chage -M sets the maximum number of days before a password change is required, and -W sets the number of days of warning before expiration. This directly enforces the 60-day maximum and 7-day warning period for the user alice, satisfying the policy.

  • ✗

    chage -m 60 -I 7 alice

    Why it's wrong here

    chage -m sets the minimum number of days between password changes, and -I sets the number of inactive days after password expiration before the account is locked. These options control different aspects and do not set a maximum age or warning period.

  • ✗

    usermod -e 2025-01-01 -f 7 alice

    Why it's wrong here

    usermod -e sets an account expiration date, not a password expiration interval, and -f sets the number of inactive days after password expiration before the account is disabled. This does not enforce a 60-day password change cycle or a 7-day warning.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.