Courseiva
Security →easyMultiple Choice

XK0-006 Security Practice Question

Which file contains user password hashes and aging information on a Linux system?

⚠ Common exam trap

A common mix-up: candidates confuse /etc/passwd with /etc/shadow, mistakenly thinking that /etc/passwd still stores password hashes, but modern Linux systems store them only in /etc/shadow for security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/shadow

The /etc/shadow file stores user password hashes along with password aging information, such as the last password change date, minimum and maximum password age, warning period, and inactivity lockout. This file is readable only by root (or privileged processes) to protect the hashed passwords from unauthorized access, unlike /etc/passwd which is world-readable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    /etc/shadow

    Why this is correct

    /etc/shadow stores the hashed passwords alongside ageing fields such as last change, minimum, maximum and warning days, which /etc/passwd does not hold. It is readable only by root, restricting hash exposure. This satisfies the requirement for both password hashes and ageing information in one file.

  • ✗

    /etc/group

    Why it's wrong here

    /etc/group maps group names to GIDs and member lists; it stores no password hashes and no aging information. It is tempting because it is a core account file alongside passwd and shadow, but its scope is group membership, not user credential or expiry data.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd holds the account database with a placeholder x in the password field, plus UID, GID, home and shell; hashes and aging were moved to /etc/shadow for security. It is tempting as the classic user file, but it no longer carries password hashes or aging data.

  • ✗

    /etc/gshadow

    Why it's wrong here

    /etc/gshadow stores group passwords and group administrators, not per-user password hashes or aging fields. It is tempting because it mirrors /etc/shadow's restricted-permission design, but that applies to group data; user hashes and aging live in /etc/shadow.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.