Courseiva
Service Configuration →easyMultiple Choice

LFCS Service Configuration Practice Question

An administrator needs to configure a service to run as a non-root user for security reasons. Which systemd unit file directive accomplishes this?

⚠ Common exam trap

Many exam-takers confuse `User=` with `Group=` or assume that `DynamicUser=yes` is the only way to run as a non-root user, missing that `User=` directly specifies a static, named user account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User=myuser

The `User=` directive in a systemd unit file specifies the user (by name or UID) under which the service process runs. By setting `User=myuser`, the service executes with the privileges of that non-root user, reducing the attack surface and adhering to the principle of least privilege. This is the standard systemd mechanism for dropping root privileges for a service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AmbientCapabilities=CAP_NET_BIND_SERVICE

    Why it's wrong here

    AmbientCapabilities grants specific Linux capabilities to the process but leaves its UID unchanged, so the service still runs as root. This directive is the right choice when a service must run as root yet be restricted to a narrow capability such as binding a privileged port.

  • ✗

    DynamicUser=yes

    Why it's wrong here

    DynamicUser allocates a transient, automatically generated UID at service start rather than the named account myuser, so it does not satisfy a requirement to run as that specific user. DynamicUser suits stateless services needing isolation without a pre-created account.

  • ✓

    User=myuser

    Why this is correct

    `User=` drops privileges to the named account before the service's main process starts, satisfying the stem's non-root requirement. systemd performs the setuid itself, so no shell wrapper or `su` is needed. Pair it with `Group=` for full control over the process credentials.

  • ✗

    Group=myuser

    Why it's wrong here

    Group= sets the supplementary group the service process runs under; it does not change the user identity, so the unit still starts as root. Group= is correct when a service must retain its default user but gain access to files owned by a particular group.

About these practice questions

This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.