Courseiva

LFCS User and Group Management Practice Question

A junior administrator created a user account with the command `useradd -m devuser`. The account was created without a password, and the administrator now wants to set an initial password so the user can log in. Which command should the administrator use to assign a password to the account?

⚠ Common exam trap

The trap here is assuming that usermod -p or useradd -p accepts a plaintext password, when both actually require an already-encrypted hash string from crypt or openssl passwd.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

passwd devuser

Assigning an initial password to an existing account is done with passwd followed by the username when executed as root. That command prompts interactively for the new secret, hashes it, and writes it to /etc/shadow, immediately enabling authentication. The other commands either expect a pre-hashed string, manage unrelated metadata, or apply only during account creation, so none of them sets a usable password here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    usermod -p devuser

    Why it's wrong here

    The -p option of usermod expects an already-encrypted password string as its argument, not a username. Running usermod -p devuser would place the literal text 'devuser' into the password field of /etc/shadow, producing an unusable and insecure hash-like entry. It does not prompt for a password and is not the correct way to assign one.

  • ✓

    passwd devuser

    Why this is correct

    The passwd command with a username argument sets or changes that account's password when run by root. It prompts for the new password twice and writes the resulting hash to /etc/shadow. This is the standard, supported way to give a newly created account its first password, and it also updates the last-change field used by password aging.

  • ✗

    chage -p devuser

    Why it's wrong here

    chage manages password aging information such as expiration dates and minimum/maximum days between changes. It does not set or store a password hash at all. Using chage -p would be interpreted incorrectly or rejected, and even if accepted it would only alter aging metadata, leaving the account still unable to authenticate because no valid password exists in /etc/shadow.

  • ✗

    useradd -p devuser

    Why it's wrong here

    The -p option of useradd also expects a pre-encrypted password value and is only meaningful at account-creation time. The account already exists, so useradd would fail with a 'user already exists' error. Even on creation, passing a plaintext username would store an invalid hash rather than a usable password, so this approach is wrong for the scenario.

About these practice questions

One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.