LFCS User and Group Management Practice Question
An administrator is auditing a server and needs to list only the users whose primary group is 'developers'. The system has many users, and the administrator wants a precise, scriptable one-liner that parses /etc/passwd. Which command accomplishes this?
⚠ Common exam trap
The trap here is comparing the numeric GID field against a group name string, or assuming the group database lists primary-group members, when primary membership lives in the passwd entry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
getent passwd | awk -F: '$4=="'"$(getent group developers | cut -d: -f3)"'" {print $1}'
The passwd database stores the primary group as a numeric GID in the fourth field, so the reliable approach is to resolve the group name to its GID and compare numerically. Using getent keeps the query consistent with NSS sources such as LDAP or SSSD, which plain file greps would miss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
getent passwd | awk -F: '$4=="'"$(getent group developers | cut -d: -f3)"'" {print $1}'
Why this is correct
This command first resolves the numeric GID of the 'developers' group via getent group, then filters /etc/passwd entries whose fourth field (GID) equals that number, printing the username. It is precise, uses NSS-aware getent, and correctly compares numeric GIDs as stored in the passwd database.
- ✗
grep developers /etc/passwd
Why it's wrong here
Searching /etc/passwd for the literal string 'developers' can match the GECOS field, home directory, or shell path, and it cannot match anything at all if the passwd file stores only the numeric GID. It does not reliably identify users whose primary group is developers.
- ✗
getent passwd | awk -F: '$4=="developers" {print $1}'
Why it's wrong here
The fourth colon-separated field in /etc/passwd and getent passwd output is the numeric GID, not the group name. Comparing it against the string 'developers' will never match, so this command silently returns no users, which is incorrect for the audit.
- ✗
getent group developers
Why it's wrong here
This prints the group entry, including its GID and supplementary members listed in /etc/group. It does not enumerate users whose primary GID is developers, because those users are recorded in /etc/passwd, not as members of the group line, so the output is incomplete for the audit.
Visual reference
Go deeper
Related to this question
About these practice questions
This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.