XK0-006 Services and User Management Practice Question
A security policy mandates that user 'alice' must change her password every 60 days and must be warned 7 days before expiration. Which command should be used to enforce this?
⚠ Common exam trap
Test-takers frequently confuse the -m (minimum days) and -M (maximum days) options of chage, or assuming passwd supports the same aging flags on all distributions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chage -M 60 -W 7 alice
The chage command directly manipulates the password aging fields in /etc/shadow. Using -M 60 enforces the maximum days a password is valid, and -W 7 provides a warning to the user seven days before expiration. This is the correct and portable method to comply with the stated security policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
passwd -x 60 -w 7 alice
Why it's wrong here
passwd -x sets the maximum password lifetime and -w sets the warning period, but these options are not available on all Linux distributions. On many systems, passwd does not support -x or -w; chage is the portable and standard tool for managing password aging information.
- ✓
chage -M 60 -W 7 alice
Why this is correct
chage -M sets the maximum number of days before a password change is required, and -W sets the number of days of warning before expiration. This directly enforces the 60-day maximum and 7-day warning period for the user alice, satisfying the policy.
- ✗
chage -m 60 -I 7 alice
Why it's wrong here
chage -m sets the minimum number of days between password changes, and -I sets the number of inactive days after password expiration before the account is locked. These options control different aspects and do not set a maximum age or warning period.
- ✗
usermod -e 2025-01-01 -f 7 alice
Why it's wrong here
usermod -e sets an account expiration date, not a password expiration interval, and -f sets the number of inactive days after password expiration before the account is disabled. This does not enforce a 60-day password change cycle or a 7-day warning.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.