Courseiva

LFCS Operation of Running Systems Practice Question

A user reports that they cannot log in via SSH, but other users can. The administrator checks /var/log/auth.log and sees 'Failed password for invalid user'. What is the most likely cause?

⚠ Common exam trap

Test-takers frequently confuse 'invalid user' (non-existent account) with 'valid user, wrong credentials' (e.g., locked account, expired password, or bad key), but the log message explicitly distinguishes between these two cases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user does not exist on the system

The log message 'Failed password for invalid user' specifically indicates that the username presented during the SSH authentication attempt does not correspond to any account in the system's user database (e.g., /etc/passwd). This is distinct from a valid user failing authentication; the SSH server (sshd) rejects the session at the authentication stage because the user does not exist. Therefore, the most likely cause is that the user account does not exist on the system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user's SSH key is not authorized

    Why it's wrong here

    Key authentication failures log 'Authentication refused' or 'publickey' errors, and sshd would still recognise the username, not report it invalid. Unauthorised keys are the cause when password auth is disabled and the user's key is missing from authorized_keys.

  • ✗

    The user account is locked

    Why it's wrong here

    A locked account still exists, so the log would name a valid user, not 'invalid user'. That message means the supplied username is absent from the system; the account is tempting because lockouts also block SSH, but they produce different log wording.

  • ✓

    The user does not exist on the system

    Why this is correct

    The message 'Failed password for invalid user' is emitted by sshd when the supplied username is absent from the local account database, so authentication fails before any password comparison. Other users succeed because their accounts exist, matching the stem's selective failure.

  • ✗

    The user's password has expired

    Why it's wrong here

    The log entry 'invalid user' means sshd rejected the account name before any password check, so expiry is never reached. Password expiry produces 'password expired' or forces a change at PAM stage. Expiry is the right diagnosis when authentication succeeds but the account is locked out pending a reset.

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.