LFCS · domain
User and Group Management
This domain covers local account and group administration on Linux: creating, modifying and deleting users and groups, password aging, the user private group scheme, and login-time defaults such as umask and shell configuration files. LFCS tests it through scenario questions where you pick the correct command, flags, or file to satisfy a stated policy.
Focused practice
Practice User and Group Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about User and Group Management
You must be able to create, modify and delete users and groups, set password aging with chage or passwd, and control login defaults like umask. The key skill is knowing which file or command flag actually takes effect last for a given user.
useradd, usermod, userdel and their flags for home directories, shells and supplementary groups
passwd -e, chage and /etc/shadow fields for password expiry and forced change
groupadd, groupmod, gpasswd and /etc/group, /etc/gshadow membership management
umask, /etc/profile, /etc/login.defs and per-user shell startup file precedence
Watch out for
Common User and Group Management exam traps
- ▸Using userdel without -r leaves the home directory and mail spool behind, failing the requirement to remove them.
- ▸Editing /etc/profile for umask when a later-read per-user file such as ~/.bashrc overrides it, so the value stays 022.
- ▸Setting expiry with usermod -e (account expiry) instead of chage/passwd -e, which controls password expiry, not the account.
Question index
All User and Group Management questions (42)
Click any question to see the full explanation, or start a practice session above.
A security policy requires that a user's password must expire 90 days after last change, and the user must change it immediately on next login. The last password change was 30 days ago. Which set of commands achieves this?
Medium2A security policy requires that user 'svc_backup' have a password that never expires. Additionally, the account should be locked after 90 days of inactivity. Which set of commands achieves this?
Hard3Which THREE commands can be used to list all users currently logged into the system?
Medium4A user 'alice' cannot log in via SSH. The administrator checks /etc/passwd and sees: alice:x:1002:1002::/home/alice:/sbin/nologin. Which command should be used to allow alice to log in with a bash shell?
Hard5Which command will display all groups a specific user belongs to, including both primary and supplementary groups?
Easy6An administrator wants to change the primary group of user 'jane' from 'staff' to 'developers'. Which command accomplishes this?
Easy7Which two commands can add an existing user to a supplementary group?
Hard8Order the steps to set up passwordless SSH key-based authentication.
Medium9A user reports that they cannot execute a file even though they are in the file's group. The file has permissions 644 and group ownership 'staff'. The user is a member of 'staff'. What is the likely issue?
Hard10A user 'dlee' reports that they cannot run 'sudo' commands despite being in the 'wheel' group. The /etc/sudoers file contains the line '%wheel ALL=(ALL) ALL'. What is the most likely cause?
Medium11A large company needs to create 100 user accounts from a list of names in a CSV file. Which tool is most efficient for batch user creation?
Medium12A junior administrator issued the command 'usermod -L alice' to lock the account of user alice. However, alice is still able to log in via SSH using a public key. What is the most likely reason?
Easy13A junior administrator created a user account with the command `useradd -m devuser`. The account was created without a password, and the administrator now wants to set an initial password so the user can log in. Which command should the administrator use to assign a password to the account?
Easy14Which THREE fields are part of a standard /etc/group entry?
Hard15A security policy requires that a user account 'temp_audit' be locked immediately without changing the password. Which command locks the account and prevents login?
Hard16Which command adds an existing user to a supplementary group without removing the user from other groups?
Easy17Which file stores the encrypted password (or password hash) for user accounts?
Easy18A security policy requires that all users in the 'admin' group must have a umask of 027 set automatically upon login. An administrator adds 'umask 027' to /etc/profile. However, users report that the umask is still 022. What is a likely cause?
Hard19Order the steps to create a systemd service unit that runs a script at boot.
Medium20An administrator needs to delete user 'obsolete' and remove its home directory and mail spool. Which command should be used?
Easy21A user must change their password at next login per security policy. The admin wants to expire the password immediately. Which command accomplishes this?
Medium22Which two commands can be used to set password expiration policies for a user?
Easy23A company follows the principle of least privilege. Several developers need sudo access to run specific commands like systemctl and journalctl. What is the best practice for granting this access?
Medium24An administrator wants to force a user to change their password at next login. Which command should be used?
Easy25An administrator needs to view a list of users who have logged in recently. Which command provides this information?
Medium26Arrange the steps to configure a new user account with sudo privileges on a Linux system.
Medium27An administrator wants to enforce that users in the 'contractors' group must change their password every 30 days, with a warning 7 days before expiry. Which command should be used?
Hard28A user named 'charlie' has just been added to the 'devops' group. However, when 'charlie' runs 'sudo -l', no sudo entries are shown. What is the most likely cause?
Hard29An administrator is auditing a server and needs to list only the users whose primary group is 'developers'. The system has many users, and the administrator wants a precise, scriptable one-liner that parses /etc/passwd. Which command accomplishes this?
Hard30A temporary contractor 'contractor1' has left the company. The administrator needs to remove the user account and all associated files in the home directory. Which command accomplishes this?
Medium31Which TWO commands can be used to display the group membership of a user? (Choose two.)
Medium32You are managing a Linux server that hosts a shared project directory /projects/alpha, owned by the group 'alpha' (GID 2001). The directory has permissions 2770 (setgid, rwx for owner and group, no access for others). User 'jane' (UID 1501) has a primary group 'staff' (GID 1001) and is not in the 'alpha' group. She reports being unable to list or modify files in /projects/alpha. You need to give her access as a member of the 'alpha' group without changing her primary group. Which command sequence should you use?
Medium33A Linux server hosts a shared project workspace at /srv/design. The directory is owned by root and currently has permissions 0775 with group ownership set to the 'designers' group. A new file was just created inside /srv/design by user 'mira' (a member of designers), and the file's group is showing as 'mira' instead of 'designers'. The team lead wants every NEW file and subdirectory created under /srv/design to automatically inherit the 'designers' group, while leaving existing files untouched. Which command should the administrator run?
Medium34Scenario: You are managing a Linux server that hosts a web application. The application runs under the user 'webapp' and the group 'webgroup'. Recently, a new intern 'john' (username 'john') needs to be able to view and modify files in /var/www/html, which is owned by root:webgroup with permissions 775. John is currently a member of the group 'staff', but not 'webgroup'. The security policy requires that John must be able to edit files without using sudo, and his primary group must remain 'staff'. Which of the following actions should you take to meet the requirements?
Medium35A system administrator needs to create a shared group 'projectx' and add existing users 'bob' and 'carol' to it. The users need to collaborate on files in a directory /projectx. What is the correct sequence of commands to set up the group and ensure new files created in /projectx are automatically owned by the group 'projectx'?
Medium36After deleting user 'alice', the system administrator wants to also remove the home directory and mail spool. Which command should be used?
Hard37Match each Linux boot component to its description.
Medium38Existing user 'jdoe' is a member of groups 'users' (primary) and 'staff'. The administrator needs to add 'jdoe' to group 'projectx' while preserving existing supplementary group memberships. Which command achieves this?
Medium39Which THREE files are directly related to user and group management in a Linux system? (Select three.)
Hard40A junior administrator needs to add user 'mchen' to the supplementary group 'developers' without removing existing group memberships. Which command should be used?
Easy41Refer to the exhibit. The administrator attempted to create a user 'newuser' but received an error. Which command should be used to check if the user already exists?
Easy42Which THREE of the following statements about the user private group (UPG) scheme are true?
HardOther domains
All LFCS exam domains
Frequently asked questions
- What does the User and Group Management domain cover on the LFCS exam?
- You must be able to create, modify and delete users and groups, set password aging with chage or passwd, and control login defaults like umask. The key skill is knowing which file or command flag actually takes effect last for a given user.
- How many questions are in this domain?
- This page lists all 42 User and Group Management questions in the LFCS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only User and Group Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.