Courseiva

CCNA User and Group Management Questions

42 questions · User and Group Management · All types, answers revealed

1
MCQmedium

A security policy requires that a user's password must expire 90 days after last change, and the user must change it immediately on next login. The last password change was 30 days ago. Which set of commands achieves this?

A.chage -M 90 user1; chage -d 0 user1
B.chage -M 90 user1; chage -m 1 user1
C.chage -M 90 user1; chage -W 7 user1
D.chage -M 90 user1; chage -I 5 user1
AnswerA

Setting `-M 90` defines the maximum password age as 90 days, satisfying the expiry constraint. Setting `-d 0` backdates the last-change date to the epoch, forcing an immediate password change at next login. Together they meet both policy requirements for user1.

Why this answer

`chage -M 90 user1` sets the maximum password age to 90 days, and `chage -d 0 user1` forces the password to expire immediately (setting the last change date to epoch 0), which requires the user to change the password on the next login. This satisfies both requirements: the password will expire 90 days after the forced change, and the user must change it immediately.

Exam trap

The trap here is that candidates may confuse `-d 0` with other `chage` options like `-M`, `-m`, `-W`, or `-I`, not realizing that only `-d 0` forces an immediate password change on next login.

How to eliminate wrong answers

Option B is wrong because `chage -m 1` sets the minimum number of days between password changes to 1, which does not force immediate expiration or enforce the 90-day expiry; it only prevents the user from changing the password more than once per day. Option C is wrong because `chage -W 7` sets a warning period of 7 days before password expiration, which does not force immediate password change on next login. Option D is wrong because `chage -I 5` sets the inactive lockout period to 5 days after expiration, which does not force immediate password change on next login.

2
MCQhard

A security policy requires that user 'svc_backup' have a password that never expires. Additionally, the account should be locked after 90 days of inactivity. Which set of commands achieves this?

A.chage -W 7 -I 90 svc_backup
B.chage -E 2025-01-01 -I 90 svc_backup
C.chage -M 99999 -I 90 svc_backup
D.chage -M 90 -I 90 svc_backup
AnswerC

The -M 99999 flag sets the maximum days between password changes to effectively never expire, meeting the no-expiry policy. The -I 90 flag sets the inactivity period, after which the account is locked, satisfying the 90-day lockout requirement precisely.

Why this answer

`chage -M 99999` sets the maximum password age to 99999 days, effectively preventing the password from ever expiring (since 99999 days far exceeds any practical lifespan). The `-I 90` flag sets the inactivity period to 90 days, meaning the account will be locked after 90 days of no login activity. This combination satisfies both security policy requirements: a non-expiring password and automatic lockout after 90 days of inactivity.

Exam trap

The trap here is that candidates often confuse `-I` (inactivity lock) with `-E` (account expiration) or assume that setting `-M 90` combined with `-I 90` will satisfy both requirements, but `-M 90` causes the password to expire, which violates the 'never expires' mandate.

How to eliminate wrong answers

Option A is wrong because `-W 7` sets a warning period of 7 days before password expiration, but it does not disable password expiration; the password will still expire based on the default maximum age (typically 99999 or a system-defined value), and `-I 90` alone does not prevent expiration. Option B is wrong because `-E 2025-01-01` sets an absolute account expiration date, which would lock the account on that date regardless of inactivity, and does not prevent password expiration; the policy requires the password to never expire, not the account to expire on a fixed date. Option D is wrong because `-M 90` sets the maximum password age to 90 days, meaning the password will expire after 90 days, contradicting the requirement that the password never expires; the `-I 90` inactivity lock would only apply after the password expires, not independently.

3
Multi-Selectmedium

Which THREE commands can be used to list all users currently logged into the system?

Select 3 answers
A.w
B.last
C.users
D.id
E.who
AnswersA, C, E

The `w` command reads `/var/run/utmp` and prints every logged-in user alongside their terminal, source host, login time and current activity, satisfying the requirement to list all users currently logged into the system. It shows the full session table rather than only the invoking user, as `whoami` would.

Why this answer

The w command (A) is correct because it reads /var/run/utmp and displays every user currently logged in along with their terminal, source host, login time, idle time, and current process. The users command (C) is correct because it prints a space-separated list of the login names of all users currently logged into the system, derived from utmp. The who command (E) is correct because it also reads utmp and lists currently logged-in users with their terminal, login time, and remote host.

The last command (B) is not correct here because it reads /var/log/wtmp and shows historical login/logout records, including past sessions, not only users currently logged in. The id command (D) is not correct because it displays the UID, GID, and group memberships of a single specified or current user rather than listing all logged-in users.

Exam trap

Candidates often confuse `last` (which shows historical logins) with `w`, `who`, or `users` (which show current logins). They may also overlook that `users` is a valid command, or mistakenly think `id` provides login status. While `w` and `who` are commonly taught, `users` is also correct and should not be dismissed.

4
MCQhard

A user 'alice' cannot log in via SSH. The administrator checks /etc/passwd and sees: alice:x:1002:1002::/home/alice:/sbin/nologin. Which command should be used to allow alice to log in with a bash shell?

A.usermod -d /home/alice alice
B.usermod -u 1002 alice
C.usermod -s /bin/bash alice
D.useradd -m -s /bin/bash alice
AnswerC

The account's login shell is set to /sbin/nologin, which deliberately blocks interactive SSH sessions. Running usermod -s /bin/bash alice rewrites the seventh field of alice's /etc/passwd entry to a valid interactive shell, directly satisfying the requirement that she log in with bash.

Why this answer

The /sbin/nologin shell in the /etc/passwd entry prevents alice from logging in via SSH. The usermod -s /bin/bash alice command changes alice's login shell to /bin/bash, allowing interactive SSH sessions. This directly addresses the shell restriction without altering other account properties.

Exam trap

The trap here is that candidates may confuse the shell field with other fields like home directory or UID, or attempt to recreate the user with useradd instead of modifying the existing account with usermod.

How to eliminate wrong answers

Option A is wrong because usermod -d /home/alice alice changes the home directory, but alice's home directory is already /home/alice, and this does not affect the login shell restriction. Option B is wrong because usermod -u 1002 alice changes the UID to 1002, which is already alice's UID, and has no impact on the shell or login ability. Option D is wrong because useradd -m -s /bin/bash alice attempts to create a new user 'alice', which will fail if the user already exists, and it does not modify the existing user's shell.

5
MCQeasy

Which command will display all groups a specific user belongs to, including both primary and supplementary groups?

A.cat /etc/passwd | grep username
B.groups username
C.id -g username
D.grep username /etc/group
AnswerB

The groups command queries both the primary group from /etc/passwd and supplementary memberships from /etc/group for the named user, printing them in a single line. This satisfies the requirement to show primary and supplementary groups together, unlike id -G which lists GIDs only.

Why this answer

The 'groups' command is the standard utility to list all group memberships for a given user, showing both the primary group (from /etc/passwd) and any supplementary groups (from /etc/group). It queries the system's group database directly, making it the correct and simplest choice for this task.

Exam trap

The trap here is that candidates often confuse 'id -g' (which shows only the primary group ID) with listing all groups, or they assume grepping /etc/group is sufficient, overlooking that the primary group is defined in /etc/passwd and supplementary groups may come from external sources.

How to eliminate wrong answers

Option A is wrong because 'cat /etc/passwd | grep username' only displays the user's primary group ID (GID) from the passwd database, not supplementary groups. Option C is wrong because 'id -g username' outputs only the numeric primary group ID, not the group names or supplementary memberships. Option D is wrong because 'grep username /etc/group' only shows lines in /etc/group where the username appears in the comma-separated member list, missing the primary group and any groups where the user is not explicitly listed (e.g., via NSS or LDAP).

6
MCQeasy

An administrator wants to change the primary group of user 'jane' from 'staff' to 'developers'. Which command accomplishes this?

A.usermod -g developers jane
B.usermod -G developers jane
C.groupmod -g developers jane
D.chgrp developers jane
AnswerA

`usermod -g` sets the user's primary group in `/etc/passwd`, which is exactly what the stem requires when changing jane's primary group from `staff` to `developers`. The lowercase `-g` targets the primary GID; uppercase `-G` would instead manage supplementary groups, leaving the primary group unchanged.

Why this answer

The `usermod -g` command changes the primary group of a user. The `-g` option specifies the new primary group (by name or GID), and the user's existing primary group is replaced. This directly accomplishes the administrator's goal of changing jane's primary group from 'staff' to 'developers'.

Exam trap

The trap here is confusing the `-g` (primary group) and `-G` (supplementary groups) options of `usermod`, leading candidates to mistakenly choose the uppercase `-G` option when the question explicitly asks for a primary group change.

How to eliminate wrong answers

Option B is wrong because `usermod -G` (uppercase) modifies the supplementary group list, not the primary group; it would add 'developers' as an additional group while leaving the primary group unchanged. Option C is wrong because `groupmod -g` changes the GID of an existing group, not the primary group of a user; it would rename or renumber the 'developers' group itself. Option D is wrong because `chgrp` changes the group ownership of files or directories, not the primary group of a user account.

7
Multi-Selecthard

Which two commands can add an existing user to a supplementary group?

Select 2 answers
A.useradd -G
B.gpasswd -a
C.addgroup
D.groupmod
E.usermod -aG
AnswersB, E

gpasswd -a user group appends the user to the named group's member list in /etc/group, granting supplementary membership without altering the primary group. It edits group membership directly, complementing usermod -aG which does the same via the user's entry.

Why this answer

Option B, gpasswd -a, is correct because gpasswd with the -a (add) flag adds an existing user to a named supplementary group, e.g. `gpasswd -a alice developers`, modifying /etc/group without altering the user's primary group. Option E, usermod -aG, is correct because usermod with -G specifies supplementary groups and the -a (append) flag ensures the listed group is added to the user's existing supplementary group set rather than replacing it, e.g. `usermod -aG developers alice`. Option A, useradd -G, is wrong here because useradd creates new accounts and its -G flag sets supplementary groups only at account-creation time, so it cannot add an already-existing user.

Option C, addgroup, is wrong because it is a Debian/Ubuntu convenience script for creating a new group (and optionally adding a user at creation), not the standard command for adding an existing user to an existing supplementary group. Option D, groupmod, is wrong because it modifies a group's attributes such as its name (-n) or GID (-g), and does not manage user membership.

Exam trap

The trap here is that candidates often confuse `usermod -G` (which replaces all supplementary groups) with `usermod -aG` (which appends), leading them to select `usermod -G` alone as correct, or they mistakenly think `useradd -G` can modify an existing user.

8
Drag & Dropmedium

Order the steps to set up passwordless SSH key-based authentication.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Key generation, copying, and testing are essential; permissions and file verification ensure security.

9
MCQhard

A user reports that they cannot execute a file even though they are in the file's group. The file has permissions 644 and group ownership 'staff'. The user is a member of 'staff'. What is the likely issue?

A.The file lacks execute permission for the group
B.The file does not have the setgid bit
C.The user's primary group is not 'staff'
D.The user is not the owner of the file
AnswerA

Permissions 644 grant read and write to the owner, and read only to group and others; no execute bit is set for any class. Group membership is irrelevant because the group triad is r--. Adding execute for the group, giving 654 or 754, is required before a 'staff' member can run the file.

Why this answer

The file has permissions 644, which means the owner has read/write (6), the group has read-only (4), and others have read-only (4). Since the user is a member of the group 'staff' but not the owner, they fall under the group permission class. The group lacks execute permission (the 'x' bit), so the user cannot execute the file.

Execute permission is required to run a file as a command or script, regardless of group membership.

Exam trap

LFCS exams often test the distinction between file ownership and group membership, trapping candidates who think being in the group automatically grants execute permission without checking the actual permission bits.

How to eliminate wrong answers

Option B is wrong because the setgid bit is not required for executing a file; it affects the effective group ID during execution, not the ability to execute. Option C is wrong because the user's primary group does not matter for file access; being a member of the file's group ('staff') is sufficient to apply group permissions. Option D is wrong because ownership is not required for execution; group membership grants the group permissions, which in this case lack execute.

10
MCQmedium

A user 'dlee' reports that they cannot run 'sudo' commands despite being in the 'wheel' group. The /etc/sudoers file contains the line '%wheel ALL=(ALL) ALL'. What is the most likely cause?

A.The user has not logged out and back in after being added to the 'wheel' group.
B.The user's primary group is not 'wheel'.
C.The 'wheel' group does not exist on the system.
D.The sudoers file must be edited with visudo, otherwise changes are ignored.
AnswerA

Group membership changes do not apply to existing sessions. If 'dlee' was added to 'wheel' while logged in, the current session still has the old group set. Logging out and back in refreshes the group memberships, allowing sudo to recognize the new group. This is a common oversight.

Why this answer

The most common reason a user cannot use sudo after being added to a group is that the group membership change has not taken effect in their current session. Linux processes inherit group memberships at login, so a new login is required. After logging out and back in, the user's session will include the 'wheel' group, and sudo will grant access according to the sudoers rule.

Exam trap

The trap here is assuming that group changes apply immediately; they require a new login session.

11
MCQmedium

A large company needs to create 100 user accounts from a list of names in a CSV file. Which tool is most efficient for batch user creation?

A.vipw
B.for loop with useradd
C.newusers
D.pwconv
AnswerC

`newusers` reads a plain-text file of colon-separated records and creates each account in one pass, satisfying the CSV batch requirement without scripting loops. It also sets passwords from the same file, unlike `useradd`, which handles a single account per invocation and would need 100 separate calls.

Why this answer

The `newusers` command is the most efficient tool for batch user creation because it reads a file in a specific format (username:password:UID:GID:comment:home_directory:shell) and can create multiple user accounts in a single pass, automatically handling password hashing and home directory creation. This avoids the overhead of scripting loops and multiple `useradd` invocations, making it ideal for bulk operations like creating 100 accounts from a CSV list.

Exam trap

The trap here is that candidates may think a `for loop with useradd` is the most flexible approach, but the LFCS exam emphasizes efficiency and built-in tools, making `newusers` the correct choice for batch operations over scripting a loop.

How to eliminate wrong answers

Option A is wrong because `vipw` is used to safely edit the /etc/passwd file with locking, not for batch user creation; it requires manual entry of each user line and does not automate account setup. Option B is wrong because while a `for loop with useradd` can technically create multiple users, it is less efficient than `newusers` as it requires separate shell calls for each user, lacks built-in batch password handling, and is more error-prone when processing a CSV file. Option D is wrong because `pwconv` is used to convert passwords to shadow passwords (creating /etc/shadow from /etc/passwd), not for creating user accounts.

12
MCQeasy

A junior administrator issued the command 'usermod -L alice' to lock the account of user alice. However, alice is still able to log in via SSH using a public key. What is the most likely reason?

A.The usermod -L command only locks the password but does not prevent SSH key-based authentication.
B.The usermod -L command only changes the user's shell to /sbin/nologin.
C.The usermod -L command requires a restart of the SSH service to take effect.
D.The usermod -L command is not effective on accounts with a UID less than 1000.
AnswerA

The usermod -L flag prepends an exclamation mark to the encrypted password field in /etc/shadow, disabling password authentication only. SSH public key authentication bypasses that field entirely, so alice's authorised_keys entry still grants access. Locking the account fully requires expiring it or removing the key.

Why this answer

The `usermod -L` command locks the user's password by placing an exclamation mark (!) in the second field of the /etc/shadow file, which prevents password-based authentication. However, SSH public key authentication does not rely on the password field; it uses the authorized_keys file and the SSH daemon's public key challenge-response mechanism. Therefore, even with a locked password, the user can still log in via SSH if their public key is present in ~/.ssh/authorized_keys.

Exam trap

The trap here is that candidates assume `usermod -L` disables all authentication methods, but it only affects password-based authentication, not SSH public key or other key-based mechanisms.

How to eliminate wrong answers

Option B is wrong because `usermod -L` does not change the user's shell; it only locks the password. Changing the shell to /sbin/nologin is done with `usermod -s /sbin/nologin` or `chsh`. Option C is wrong because `usermod -L` takes effect immediately on the password database; no SSH service restart is required, as SSH checks the password status at each authentication attempt.

Option D is wrong because `usermod -L` works on any user account regardless of UID; there is no UID threshold for password locking, and the command affects all users with entries in /etc/shadow.

13
MCQeasy

A junior administrator created a user account with the command `useradd -m devuser`. The account was created without a password, and the administrator now wants to set an initial password so the user can log in. Which command should the administrator use to assign a password to the account?

A.usermod -p devuser
B.passwd devuser
C.chage -p devuser
D.useradd -p devuser
AnswerB

The passwd command with a username argument sets or changes that account's password when run by root. It prompts for the new password twice and writes the resulting hash to /etc/shadow. This is the standard, supported way to give a newly created account its first password, and it also updates the last-change field used by password aging.

Why this answer

Assigning an initial password to an existing account is done with passwd followed by the username when executed as root. That command prompts interactively for the new secret, hashes it, and writes it to /etc/shadow, immediately enabling authentication. The other commands either expect a pre-hashed string, manage unrelated metadata, or apply only during account creation, so none of them sets a usable password here.

Exam trap

The trap here is assuming that usermod -p or useradd -p accepts a plaintext password, when both actually require an already-encrypted hash string from crypt or openssl passwd.

14
Multi-Selecthard

Which THREE fields are part of a standard /etc/group entry?

Select 3 answers
A.Group password (often 'x')
B.Primary GID of user
C.Group name
D.Home directory of group
E.Group members list
AnswersA, C, E

The group password field, usually shown as 'x', occupies the second colon-separated position in /etc/group, between the group name and GID. It satisfies the stem's requirement for a standard field, since shadowed group passwords live in /etc/gshadow while this placeholder remains in the entry.

Why this answer

A standard /etc/group entry has four colon-separated fields: group name, group password, group ID (GID), and group members list. Option C (group name) is correct because the first field of each /etc/group line is the group's name, such as 'sudo' or 'developers'. Option A (group password, often 'x') is correct because the second field holds the group password placeholder, typically 'x' when shadow group passwords are used via /etc/gshadow.

Option E (group members list) is correct because the fourth field is a comma-separated list of supplementary members of the group. Option B (primary GID of user) is not part of /etc/group; a user's primary GID is stored in the fourth field of /etc/passwd. Option D (home directory of group) does not exist in /etc/group; home directories are per-user fields in /etc/passwd, not per-group fields.

Exam trap

The trap here is that candidates often confuse the fields of /etc/group with those of /etc/passwd, mistakenly thinking that a group entry includes a primary GID or home directory, which are user-specific attributes stored in /etc/passwd.

15
MCQhard

A security policy requires that a user account 'temp_audit' be locked immediately without changing the password. Which command locks the account and prevents login?

A.userdel temp_audit
B.usermod -L temp_audit
C.chage -E 0 temp_audit
D.passwd -u temp_audit
AnswerB

usermod -L prefixes the password hash in /etc/shadow with an exclamation mark, immediately preventing password-based login while leaving the stored hash unchanged. This locks the account without altering the password, exactly as the policy requires.

Why this answer

The `usermod -L` command locks a user account by placing an exclamation mark (!) at the beginning of the password hash in /etc/shadow, effectively disabling password-based authentication without altering the existing password. This satisfies the security policy requirement to immediately prevent login without changing the password.

Exam trap

The trap here is confusing `usermod -L` with `passwd -l` (which also locks the account) or mistaking `chage -E 0` for an immediate lock, when in fact `chage` sets a future expiration date and does not prevent all authentication methods like SSH keys or sudo.

How to eliminate wrong answers

Option A is wrong because `userdel temp_audit` deletes the user account entirely, which violates the requirement to lock the account without changing the password. Option C is wrong because `chage -E 0` sets the account expiration date to epoch (January 1, 1970), which locks the account but is not immediate if the current date is already past epoch; it also does not prevent all login methods (e.g., SSH keys may still work depending on PAM configuration). Option D is wrong because `passwd -u temp_audit` unlocks the account (the -u flag means unlock), which is the opposite of the required action.

16
MCQeasy

Which command adds an existing user to a supplementary group without removing the user from other groups?

A.groupmod -a username groupname
B.usermod -A groupname username
C.usermod -aG groupname username
D.usermod -g groupname username
AnswerC

The -a flag appends the group to the user's existing supplementary group list rather than replacing it; without -a, usermod -G would overwrite all current supplementary memberships. This preserves the user's other groups while adding the new one.

Why this answer

The correct command is `usermod -aG groupname username`. The `-a` option (append) combined with `-G` (supplementary groups) adds the user to the specified group without affecting existing supplementary group memberships. Option A (`groupmod -a`) is incorrect because `groupmod` modifies group attributes, not user membership.

Option B (`-A`) is not a valid `usermod` option. Option D (`-g`) changes the user's primary group, not supplementary groups.

17
MCQeasy

Which file stores the encrypted password (or password hash) for user accounts?

A./etc/group
B./etc/shadow
C./etc/passwd
D./etc/gshadow
AnswerB

The /etc/shadow file holds the encrypted password hash, readable only by root, unlike the world-readable /etc/passwd which merely stores an 'x' placeholder. This satisfies the requirement to identify where the actual password hash for user accounts is kept.

Why this answer

/etc/shadow is correct because it stores encrypted password hashes for user accounts, along with password aging information. It is readable only by root to prevent unauthorized access to password hashes. The /etc/passwd file historically stored passwords but now only contains user account information, with the password field replaced by an 'x' indicating the hash is in /etc/shadow.

Exam trap

The trap is assuming that /etc/passwd still stores passwords, as it did in early Unix systems. Candidates must remember that modern systems use /etc/shadow for password hashes, and /etc/passwd only contains a placeholder.

How to eliminate wrong answers

Option A is wrong because /etc/group stores group information, not user passwords. Option C is wrong because /etc/passwd stores user account information but not the password hash; it contains a placeholder 'x' in the password field. Option D is wrong because /etc/gshadow stores group passwords and group administrators, not user passwords.

18
MCQhard

A security policy requires that all users in the 'admin' group must have a umask of 027 set automatically upon login. An administrator adds 'umask 027' to /etc/profile. However, users report that the umask is still 022. What is a likely cause?

A.The umask in /etc/profile is overridden by user-specific .bash_profile or .bashrc files.
B.The umask command in /etc/profile has a syntax error that is silently ignored.
C.The admin placed the umask command after the call to /etc/bash.bashrc which resets it.
D.The admin forgot to run 'source /etc/profile' on each user's session.
AnswerA

Login shells read /etc/profile first, then ~/.bash_profile, ~/.bash_login or ~/.profile. If any of these later files sets umask 022, it overwrites the earlier 027 value, so the policy fails despite the correct edit to /etc/profile.

Why this answer

User-specific shell configuration files (like ~/.bash_profile, ~/.bash_login, or ~/.profile for login shells, and ~/.bashrc for interactive non-login shells) are sourced after /etc/profile. These files can override the system-wide umask setting with a user-defined value, such as the default 022. Since the administrator only modified /etc/profile, any existing user-specific umask command in their personal dotfiles will take precedence.

Exam trap

The trap here is that candidates assume /etc/profile is the final authority for login shell settings, but they overlook that user-specific dotfiles are sourced after it and can override variables like umask.

How to eliminate wrong answers

Option B is wrong because the 'umask 027' command has no syntax error; umask accepts a three-digit octal value and is not silently ignored—if there were a syntax error, the shell would display an error message. Option C is wrong because /etc/bash.bashrc is typically sourced for interactive non-login shells, not for login shells where /etc/profile is read first; moreover, the order of sourcing does not cause a reset unless a later file explicitly changes the umask. Option D is wrong because /etc/profile is automatically sourced by the login shell for all users when they log in; running 'source /etc/profile' manually is unnecessary and not part of standard login procedures.

19
Drag & Dropmedium

Order the steps to create a systemd service unit that runs a script at boot.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating the unit file, enabling for boot, starting, and checking status are standard steps.

20
MCQeasy

An administrator needs to delete user 'obsolete' and remove its home directory and mail spool. Which command should be used?

A.userdel -f obsolete
B.userdel -r obsolete
C.userdel obsolete
D.groupdel obsolete
AnswerB

The -r flag instructs userdel to remove the account together with its home directory and mail spool. Without -r, those files persist as orphans, so this satisfies the stem's explicit requirement to delete both the user and associated data.

Why this answer

The correct command is `userdel -r obsolete` because the `-r` flag removes the user's home directory and mail spool in addition to deleting the user account. This matches the requirement to delete the user 'obsolete' along with its home directory and mail spool, as specified in the question.

Exam trap

The trap here is that candidates may confuse the `-r` flag with the `-f` flag, assuming `-f` (force) also removes files, or they may think `userdel` alone is sufficient, missing the requirement to clean up the home directory and mail spool.

How to eliminate wrong answers

Option A is wrong because `userdel -f` forces the removal of the user even if they are logged in, but it does not remove the home directory or mail spool; the `-f` flag is for force, not for recursive removal. Option C is wrong because `userdel obsolete` only removes the user account without deleting the home directory or mail spool, leaving those files orphaned. Option D is wrong because `groupdel obsolete` is used to delete a group, not a user, and it does not affect the user's home directory or mail spool.

21
MCQmedium

A user must change their password at next login per security policy. The admin wants to expire the password immediately. Which command accomplishes this?

A.passwd -f username
B.usermod -p '' username
C.chage -M 90 username
D.chage -d 0 username
AnswerD

`chage -d 0 username` sets the last-password-change date to the epoch, so the system treats the password as aged beyond its maximum lifetime and forces a change at next login. This directly satisfies the immediate-expiry constraint, unlike `passwd -e`, which achieves the same via a different flag.

Why this answer

The chage -d 0 username command sets the 'last password change' date to 0 (January 1, 1970), which forces the user to change their password at the next login. This is the standard Linux method to immediately expire a user's password without disabling the account.

Exam trap

LFCS often tests the confusion between password expiration (chage -d 0) and password aging policies (chage -M), or between passwd options and chage options, causing candidates to pick a command that sets a future expiration instead of immediate expiration.

How to eliminate wrong answers

Option A is wrong because passwd -f username only sets the 'force change' flag in some Unix variants (like Solaris), but on Linux it is not the correct way to expire a password; the -f option in Linux passwd is used to force a password change but is not the standard method and may not be available. Option B is wrong because usermod -p '' username sets the password field to an empty string, which effectively disables password authentication or sets a blank password, not expire it. Option C is wrong because chage -M 90 username sets the maximum password age to 90 days, which does not expire the password immediately; it only sets a future expiration.

22
Multi-Selecteasy

Which two commands can be used to set password expiration policies for a user?

Select 2 answers
A.usermod
B.passwd
C.chage
D.expiry
E.pwconv
AnswersB, C

The passwd command, via its -e, -n, -x, -w and -i options, sets password expiration fields such as maximum age, minimum age and warning period for a user. This satisfies the requirement for a command that configures password expiration policy.

Why this answer

The `passwd` command (option B) can set password expiration policies for a user via options such as `-e` (expire immediately), `-n` (minimum days), `-x` (maximum days), `-w` (warning days), and `-i` (inactive days), e.g., `passwd -x 90 -n 7 -w 14 user`. The `chage` command (option C) is specifically designed to modify password aging information in `/etc/shadow`, using flags like `-M` (max days), `-m` (min days), `-W` (warn days), `-I` (inactive days), and `-E` (account expiration date), e.g., `chage -M 90 -W 14 user`. The other options do not belong: `usermod` (A) manages account properties like groups, shell, and home directory but does not set password aging fields; `expiry` (D) is not a standard Linux command for this purpose; and `pwconv` (E) creates or updates `/etc/shadow` from `/etc/passwd` rather than setting expiration policies.

Exam trap

The trap here is that candidates often confuse `usermod` with `chage` because `usermod` can lock accounts, but it cannot set password aging parameters like maximum days or warning periods.

23
MCQmedium

A company follows the principle of least privilege. Several developers need sudo access to run specific commands like systemctl and journalctl. What is the best practice for granting this access?

A.Use 'usermod -a -G sudo' for each developer and edit /etc/sudoers manually with visudo
B.Create a new group 'devops', add developers to it, and create a sudoers drop-in file with rules for specific commands
C.Add all developers to the 'wheel' group and configure %wheel ALL=(ALL) ALL
D.Edit /etc/sudoers directly to add each developer username with command restrictions
AnswerB

A dedicated group with a sudoers drop-in file scopes privileges to named binaries, satisfying least privilege without granting full root or editing the main sudoers file. Command-level rules let developers run systemctl and journalctl only, and group membership simplifies later revocation.

Why this answer

It follows the principle of least privilege by creating a dedicated 'devops' group and using a sudoers drop-in file (e.g., /etc/sudoers.d/devops) to grant only specific commands like systemctl and journalctl. This avoids modifying the main /etc/sudoers file directly, which is error-prone, and ensures that developers have no more privileges than necessary. The drop-in file approach is the recommended best practice for maintainability and security.

Exam trap

The trap here is that candidates often default to adding users to the 'sudo' or 'wheel' group for convenience, overlooking the principle of least privilege and the proper use of sudoers drop-in files for command-specific restrictions.

How to eliminate wrong answers

Option A is wrong because using 'usermod -a -G sudo' adds developers to the 'sudo' group, which typically grants full root access via %sudo ALL=(ALL:ALL) ALL, violating least privilege. Option C is wrong because adding developers to the 'wheel' group with %wheel ALL=(ALL) ALL grants unrestricted root access, which is excessive and insecure. Option D is wrong because editing /etc/sudoers directly is error-prone and not scalable; the best practice is to use a drop-in file in /etc/sudoers.d/ for granular command restrictions.

24
MCQeasy

An administrator wants to force a user to change their password at next login. Which command should be used?

A.passwd -l user
B.passwd -e user
C.chage -m 0 user
D.usermod -p '!' user
AnswerB

passwd -e user expires the account's password immediately, setting the shadow field so the next login forces a change. This directly satisfies the requirement to force a password change at next login, unlike -l or -d which lock or clear it.

Why this answer

The `passwd -e user` command immediately expires the user's password, forcing them to change it at the next login. This is the standard method to achieve this requirement on Linux systems.

Exam trap

The trap here is confusing account locking (`passwd -l` or `usermod -p '!'`) with password expiration, as both prevent normal login but only expiration forces a password change at next login.

How to eliminate wrong answers

Option A is wrong because `passwd -l user` locks the user account, preventing any login, rather than forcing a password change. Option C is wrong because `chage -m 0 user` sets the minimum number of days between password changes to 0, which allows the user to change their password immediately but does not force a change at next login. Option D is wrong because `usermod -p '!' user` sets the password field to an invalid value (starting with '!'), which effectively locks the account, not forcing a password change.

25
MCQmedium

An administrator needs to view a list of users who have logged in recently. Which command provides this information?

A.users
B.who
C.finger
D.last
AnswerD

last reads /var/log/wtmp, which records every login and logout session, so it lists users who logged in recently with timestamps. who and w show only currently active sessions, and lastlog reports each account's most recent login only.

Why this answer

The `last` command reads the `/var/log/wtmp` file to display a list of all users who have logged in and out, including recent login sessions. This makes it the correct choice for viewing a history of recent logins, as it provides timestamps, duration, and originating host information.

Exam trap

The trap here is that candidates often confuse `who` or `users` (which show current sessions) with `last` (which shows historical login records), leading them to pick a command that only displays active users rather than recent login history.

How to eliminate wrong answers

Option A is wrong because `users` only shows the usernames of currently logged-in users, not a history of recent logins. Option B is wrong because `who` displays information about currently logged-in users (including terminal and login time), but does not show historical login records. Option C is wrong because `finger` can show a user's last login time from `/var/log/lastlog`, but it does not provide a comprehensive list of all recent login events and is not the standard command for viewing a login history.

26
Drag & Dropmedium

Arrange the steps to configure a new user account with sudo privileges on a Linux system.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

After creating the user and setting a password, adding to the wheel group grants sudo access. Verification and testing confirm it works.

27
MCQhard

An administrator wants to enforce that users in the 'contractors' group must change their password every 30 days, with a warning 7 days before expiry. Which command should be used?

A.groupmod -p 30 contractors
B.passwd -x 30 -w 7 contractors
C.usermod -e 30 contractors
D.chage -M 30 -W 7 contractors
AnswerD

Incorrect. `chage -M 30 -W 7` is the right command for password aging, but it requires a username, not a group name.

Why this answer

None of the provided commands can be directly applied to a group. The `chage` command is the appropriate tool for password aging, but it requires a username as an argument. To enforce password aging on all users in the 'contractors' group, an administrator would need to iterate over each user in the group and run `chage -M 30 -W 7 <username>` for each.

Exam trap

The trap is that candidates may think `chage` can take a group name, but it requires a username. Also, `passwd` has similar aging options but also requires a username.

How to eliminate wrong answers

Option A is wrong because `groupmod` is used to modify group properties (like GID or group name), not password aging; the `-p` flag does not exist for password expiration. Option B is wrong because `passwd` with `-x` and `-w` can set password aging for a user, but the syntax requires a username, not a group name; it cannot be applied to a group directly. Option C is wrong because `usermod -e` sets an account expiration date (a specific date), not a password aging interval; it does not enforce a 30-day password change cycle.

28
MCQhard

A user named 'charlie' has just been added to the 'devops' group. However, when 'charlie' runs 'sudo -l', no sudo entries are shown. What is the most likely cause?

A.'charlie' is not listed by name in the sudoers file.
B.'charlie' must log out and log back in for the group change to take effect.
C.'charlie' is also a member of another group that restricts sudo.
D.The systemctl command is not executable by 'charlie'.
E.The sudoers file has a syntax error.
AnswerB

Group membership is resolved at login and cached in the session's credential set. Charlie's existing shell still holds the old groups, so sudo matches no rule. Logging out and back in refreshes the supplementary group list, making the devops sudo entries visible.

Why this answer

When a user is added to a new group, the group membership is only applied to new login sessions. The `sudo -l` command checks the user's current group memberships, which are cached at login time. Since 'charlie' was added to the 'devops' group while already logged in, the new group membership is not reflected until 'charlie' logs out and logs back in, or uses `newgrp` or `sg` to start a new session with the updated groups.

Exam trap

The trap here is that candidates assume group changes are immediate for all processes, but Linux caches group membership at login time, so `sudo -l` reflects only the groups present when the session started.

How to eliminate wrong answers

Option A is wrong because the sudoers file can grant sudo access via group membership (e.g., `%devops ALL=(ALL) ALL`), so 'charlie' does not need to be listed by name; the group membership should suffice. Option C is wrong because being a member of another group does not restrict sudo unless that group is explicitly denied in sudoers; group membership is additive, not restrictive. Option D is wrong because the `systemctl` command's executability is irrelevant to `sudo -l` showing entries; `sudo -l` displays the commands the user is allowed to run, not whether a specific command is executable.

Option E is wrong because a syntax error in the sudoers file would typically cause `sudo` to fail with an error message (e.g., 'syntax error near line X'), not silently show no entries.

29
MCQhard

An administrator is auditing a server and needs to list only the users whose primary group is 'developers'. The system has many users, and the administrator wants a precise, scriptable one-liner that parses /etc/passwd. Which command accomplishes this?

A.getent passwd | awk -F: '$4=="'"$(getent group developers | cut -d: -f3)"'" {print $1}'
B.grep developers /etc/passwd
C.getent passwd | awk -F: '$4=="developers" {print $1}'
D.getent group developers
AnswerA

This command first resolves the numeric GID of the 'developers' group via getent group, then filters /etc/passwd entries whose fourth field (GID) equals that number, printing the username. It is precise, uses NSS-aware getent, and correctly compares numeric GIDs as stored in the passwd database.

Why this answer

The passwd database stores the primary group as a numeric GID in the fourth field, so the reliable approach is to resolve the group name to its GID and compare numerically. Using getent keeps the query consistent with NSS sources such as LDAP or SSSD, which plain file greps would miss.

Exam trap

The trap here is comparing the numeric GID field against a group name string, or assuming the group database lists primary-group members, when primary membership lives in the passwd entry.

30
MCQmedium

A temporary contractor 'contractor1' has left the company. The administrator needs to remove the user account and all associated files in the home directory. Which command accomplishes this?

A.userdel contractor1
B.passwd -d contractor1
C.userdel -r contractor1
D.deluser --remove-home contractor1
AnswerC

`userdel -r contractor1` deletes the account and recursively removes the home directory with its mail spool, satisfying the requirement to erase all associated files. Plain `userdel` would leave `/home/contractor1` intact, so the `-r` flag is essential here.

Why this answer

The `userdel -r contractor1` command removes the user account and, with the `-r` flag, also deletes the user's home directory and mail spool. This is the standard Linux command to completely remove a user and their associated files, as required by the scenario.

Exam trap

The trap here is that candidates may choose Option A, thinking `userdel` alone removes everything, or Option D, assuming `deluser` is universally available, when the LFCS exam tests the standard `userdel -r` command that works across all major Linux distributions.

How to eliminate wrong answers

Option A is wrong because `userdel contractor1` removes the user account but leaves the home directory and its files intact, failing to meet the requirement to remove all associated files. Option B is wrong because `passwd -d contractor1` only deletes the user's password, allowing password-less login, and does not remove the account or any files. Option D is wrong because `deluser --remove-home contractor1` is a Debian/Ubuntu-specific command, not a standard command on all Linux distributions (e.g., RHEL/CentOS), and the LFCS exam expects distribution-agnostic commands like `userdel -r`.

31
Multi-Selectmedium

Which TWO commands can be used to display the group membership of a user? (Choose two.)

Select 2 answers
A.id -Gn username
B.cat /etc/passwd | grep username
C.id -g username
D.groups username
E.grep username /etc/group
AnswersA, D

id -Gn username prints only the supplementary group names for that user, one line of space-separated groups, which directly answers the membership query. It reads the same account database entries as id without the numeric UID and GID output.

Why this answer

Option A, 'id -Gn username', is correct because the -G flag lists all group IDs the user belongs to and -n converts those GIDs to group names, so it prints every group name the user is a member of. Option D, 'groups username', is correct because the groups command prints the group names that the specified user belongs to, directly showing group membership. Option B, 'cat /etc/passwd | grep username', only shows the user's passwd entry, which contains the primary GID but not supplementary group memberships.

Option C, 'id -g username', prints only the primary group ID (or name with -n), not the full set of groups. Option E, 'grep username /etc/group', only finds groups where the username appears in the member list and misses the user's primary group, so it does not reliably display complete group membership.

Exam trap

The trap is picking file-based commands (/etc/passwd, /etc/group) that only show partial membership, instead of the NSS-aware commands (id -Gn, groups) that report complete group membership.

32
MCQmedium

You are managing a Linux server that hosts a shared project directory /projects/alpha, owned by the group 'alpha' (GID 2001). The directory has permissions 2770 (setgid, rwx for owner and group, no access for others). User 'jane' (UID 1501) has a primary group 'staff' (GID 1001) and is not in the 'alpha' group. She reports being unable to list or modify files in /projects/alpha. You need to give her access as a member of the 'alpha' group without changing her primary group. Which command sequence should you use?

A.usermod -aG alpha jane; usermod -G '' jane; usermod -aG alpha jane
B.usermod -aG alpha jane
C.usermod -g alpha jane
D.usermod -G alpha jane
AnswerB

usermod -aG alpha jane appends jane to the alpha supplementary group without altering her primary group staff, satisfying the constraint. The setgid bit on /projects/alpha then grants group access, letting her list and modify files after re-login.

Why this answer

The command `usermod -aG alpha jane` appends jane to the supplementary group 'alpha' without altering her primary group 'staff'. Because /projects/alpha is group-owned by alpha with 2770 permissions, group membership grants rwx access, and the setgid bit ensures new files inherit the alpha group. This satisfies the requirement of granting access without changing her primary group.

Exam trap

LFCS often tests the difference between `-g` (change primary group) and `-aG` (append supplementary group) — candidates who omit `-a` accidentally wipe existing supplementary memberships.

How to eliminate wrong answers

Option A is wrong because it needlessly removes jane from all supplementary groups (`usermod -G '' jane`) before re-adding alpha, which strips any other group memberships she legitimately needs and is destructive. Option C is wrong because `usermod -g alpha jane` changes her primary group to alpha, which the question explicitly forbids. Option D is wrong because `usermod -G alpha jane` (without -a) replaces her entire supplementary group list with only alpha, silently removing her from all other supplementary groups.

33
MCQmedium

A Linux server hosts a shared project workspace at /srv/design. The directory is owned by root and currently has permissions 0775 with group ownership set to the 'designers' group. A new file was just created inside /srv/design by user 'mira' (a member of designers), and the file's group is showing as 'mira' instead of 'designers'. The team lead wants every NEW file and subdirectory created under /srv/design to automatically inherit the 'designers' group, while leaving existing files untouched. Which command should the administrator run?

A.chmod g+s /srv/design
B.chgrp -R designers /srv/design
C.setfacl -R -m g:designers:rwx /srv/design
D.chmod +t /srv/design
AnswerA

Setting the setgid bit on a directory (chmod g+s) causes all newly created files and subdirectories within it to inherit the directory's group instead of the creating user's primary group. This matches the requirement exactly and does not modify existing file ownership or group memberships.

Why this answer

The setgid bit on a directory is the standard mechanism for group inheritance: any file or subdirectory created inside the directory takes the directory's group as its own group. Using chmod g+s on /srv/design applies this behavior without touching existing files or changing individual user group memberships.

Exam trap

The trap here is assuming that adding an ACL or recursively changing group ownership will make future files inherit the group, when only the directory setgid bit provides persistent group inheritance.

34
MCQmedium

Scenario: You are managing a Linux server that hosts a web application. The application runs under the user 'webapp' and the group 'webgroup'. Recently, a new intern 'john' (username 'john') needs to be able to view and modify files in /var/www/html, which is owned by root:webgroup with permissions 775. John is currently a member of the group 'staff', but not 'webgroup'. The security policy requires that John must be able to edit files without using sudo, and his primary group must remain 'staff'. Which of the following actions should you take to meet the requirements?

A.Add John to the 'webgroup' supplementary group with 'usermod -a -G webgroup john'.
B.Change the group ownership of /var/www/html to 'staff' and set the setgid bit.
C.Change John's primary group to 'webgroup' with 'usermod -g webgroup john'.
D.Set the setgid bit on /var/www/html with 'chmod g+s /var/www/html'.
AnswerA

Adding john to webgroup as a supplementary group grants him the group write permission on /var/www/html (775, root:webgroup) without sudo, while his primary group stays staff. This satisfies both the editing requirement and the policy that his primary group remain unchanged.

Why this answer

Adding John to the 'webgroup' supplementary group with `usermod -a -G webgroup john` grants him group-level access to /var/www/html (owned by root:webgroup with permissions 775) without changing his primary group 'staff'. This allows him to view and modify files as a member of 'webgroup', satisfying the security policy that he must not use sudo and his primary group must remain unchanged.

Exam trap

The trap here is that candidates may confuse the setgid bit (Option D) with granting group membership, or incorrectly assume that changing the primary group (Option C) is acceptable despite the explicit requirement to keep it as 'staff'.

How to eliminate wrong answers

Option B is wrong because changing the group ownership of /var/www/html to 'staff' would grant access to all members of 'staff', which violates the principle of least privilege and does not specifically give John access as a member of 'webgroup'. Option C is wrong because changing John's primary group to 'webgroup' with `usermod -g webgroup john` would violate the requirement that his primary group must remain 'staff'. Option D is wrong because setting the setgid bit on /var/www/html with `chmod g+s /var/www/html` only ensures new files inherit the group ownership of the directory, but does not grant John membership in 'webgroup' or access to the directory itself.

35
MCQmedium

A system administrator needs to create a shared group 'projectx' and add existing users 'bob' and 'carol' to it. The users need to collaborate on files in a directory /projectx. What is the correct sequence of commands to set up the group and ensure new files created in /projectx are automatically owned by the group 'projectx'?

A.groupadd projectx; usermod -G projectx bob carol; chmod 2770 /projectx
B.addgroup projectx; adduser bob projectx; adduser carol projectx; chmod u+s /projectx
C.groupadd projectx; usermod -aG projectx bob; usermod -aG projectx carol; chmod g+s /projectx
D.groupadd projectx; usermod -G projectx bob; usermod -G projectx carol; chmod g+s /projectx
AnswerC

groupadd creates the group, usermod -aG appends bob and carol as supplementary members without disturbing their primary groups, and chmod g+s sets the setgid bit on /projectx so new files inherit the projectx group rather than each creator's primary group.

Why this answer

It uses `groupadd` to create the group, `usermod -aG` to append users to the group without removing them from other groups, and `chmod g+s` to set the setgid bit on the directory. The setgid bit ensures that new files created in /projectx inherit the group ownership of the directory (projectx), enabling collaboration.

Exam trap

The trap here is that `usermod -G` without `-a` overwrites the user's supplementary groups, and candidates often forget the `-a` flag, leading to accidental removal of existing group memberships.

How to eliminate wrong answers

Option A is wrong because `usermod -G` without `-a` replaces the user's supplementary group list, removing any existing supplementary groups, which can cause loss of access. Option B is wrong because `adduser` and `addgroup` are distribution-specific (Debian/Ubuntu) and not standard on all Linux systems; also `chmod u+s` sets the setuid bit (affects user ownership, not group), which does not enforce group ownership inheritance. Option D is wrong because `usermod -G` without `-a` overwrites the user's supplementary groups, potentially removing them from other groups they need.

36
MCQhard

After deleting user 'alice', the system administrator wants to also remove the home directory and mail spool. Which command should be used?

A.userdel -Z alice
B.userdel -r alice
C.userdel -f alice
D.userdel --remove alice
AnswerB

`userdel -r alice` removes the account plus its home directory and mail spool in one pass, satisfying the stem's requirement to clear both artefacts after deletion. The `-r` flag triggers that cleanup; plain `userdel` leaves `/home/alice` and `/var/mail/alice` intact.

Why this answer

The correct option is B, userdel -r alice. The -r flag removes the user's home directory and mail spool, along with the user account. This is the standard flag for removing user data along with the account.

37
Matchingmedium

Match each Linux boot component to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Boot loader that loads the kernel

Initial RAM filesystem used before root is mounted

Init system and service manager

Core of the operating system

Program that loads the OS into memory

Why these pairings

The correct matches are: BIOS/UEFI initializes hardware and loads the bootloader; Initramfs is the temporary root filesystem; Systemd is the init system. Common confusions occur between kernel and bootloader roles.

38
MCQmedium

Existing user 'jdoe' is a member of groups 'users' (primary) and 'staff'. The administrator needs to add 'jdoe' to group 'projectx' while preserving existing supplementary group memberships. Which command achieves this?

A.usermod -g projectx -G projectx jdoe
B.usermod -g projectx jdoe
C.usermod -G projectx jdoe
D.usermod -a -G projectx jdoe
AnswerD

The -a flag appends projectx to jdoe's supplementary group list, while -G specifies the group. Omitting -a would overwrite the existing supplementary membership, dropping staff. This preserves users and staff while adding projectx, exactly as the stem requires.

Why this answer

The `-a` (append) flag combined with `-G` (supplementary groups) adds the user to the specified group without removing existing supplementary group memberships. Without `-a`, the `-G` flag replaces all supplementary groups with the listed ones, which would remove the 'staff' group membership.

Exam trap

The trap here is that candidates forget the `-a` flag is required with `-G` to append groups, assuming `-G` alone adds groups instead of replacing them.

How to eliminate wrong answers

Option A is wrong because it sets the primary group to 'projectx' with `-g` and also sets supplementary groups to only 'projectx' with `-G`, which would remove 'staff' and change the primary group from 'users'. Option B is wrong because `-g` changes only the primary group to 'projectx', leaving supplementary groups unchanged but incorrectly altering the primary group. Option C is wrong because `-G projectx` without `-a` replaces all supplementary group memberships with only 'projectx', removing 'staff'.

39
Multi-Selecthard

Which THREE files are directly related to user and group management in a Linux system? (Select three.)

Select 3 answers
A./etc/sudoers
B./etc/login.defs
C./etc/group
D./etc/passwd
E./etc/shadow
AnswersC, D, E

/etc/group stores group names, GIDs and membership lists, forming the core database consulted by group management tools. It is directly related to user and group management, unlike unrelated system files such as /etc/fstab or /etc/hosts.

Why this answer

The three files directly related to user and group management are /etc/group (C), /etc/passwd (D), and /etc/shadow (E). /etc/passwd stores user account entries with UID, GID, home directory, and login shell, making it a core user-management file. /etc/group defines group names, GIDs, and group membership lists, so it is essential for group management. /etc/shadow stores encrypted password hashes and password-aging fields for local users, which is a fundamental part of user account administration. /etc/sudoers (A) controls sudo privilege delegation, and /etc/login.defs (B) sets defaults for login and user-creation tools; both are related to authentication or account policy, but they are not the primary user/group database files.

Exam trap

The trap here is that candidates may confuse configuration files like /etc/sudoers or /etc/login.defs with the actual user/group database files, but the question specifically asks for files 'directly related to user and group management'—meaning the files that store the user and group records themselves, not files that configure how those records are created or used.

40
MCQeasy

A junior administrator needs to add user 'mchen' to the supplementary group 'developers' without removing existing group memberships. Which command should be used?

A.usermod -aG developers mchen
B.usermod -G developers mchen
C.groupmod -a -U mchen developers
D.gpasswd -a mchen developers
AnswerA

The -aG option appends the specified group to the user's supplementary group list. Without -a, usermod -G would replace all existing supplementary groups. This command preserves current memberships and adds 'developers', which is exactly what is needed.

Why this answer

To add a user to a supplementary group while preserving existing memberships, use usermod with the -a (append) and -G (supplementary groups) options. Without -a, the -G option replaces all supplementary groups. This command safely adds the new group without affecting others, ensuring the user retains all necessary access.

Exam trap

The trap here is forgetting the -a flag, which leads to replacing all supplementary groups instead of appending.

41
MCQeasy

Refer to the exhibit. The administrator attempted to create a user 'newuser' but received an error. Which command should be used to check if the user already exists?

A.cat /etc/passwd | grep newuser
B.passwd -S newuser
C.usermod -c newuser
D.userdel -v newuser
AnswerA

Searching `/etc/passwd` for the string `newuser` directly confirms whether the account already exists, since local users are recorded there. Piping `cat` into `grep` satisfies the stem's requirement to check for a pre-existing user before retrying `useradd`, which failed because the name was already taken.

Why this answer

The /etc/passwd file stores all user account information, and using cat to pipe its contents through grep allows the administrator to search for the specific username 'newuser'. If the user exists, grep will output the matching line; if not, no output is returned. This is a standard, quick method to verify user existence without modifying system state.

Exam trap

The trap here is that candidates may choose a command that seems related to user management (like passwd or usermod) without realizing those commands assume the user already exists and will produce errors or unintended side effects when used for existence verification.

How to eliminate wrong answers

Option B is wrong because 'passwd -S newuser' displays the status of a user's password (e.g., locked, password set), but it will fail with an error if the user does not exist, making it unsuitable for checking existence without causing an error. Option C is wrong because 'usermod -c newuser' attempts to modify the comment field of an existing user named 'newuser', which will fail if the user does not exist; the -c flag expects a comment string, not a username to check. Option D is wrong because 'userdel -v newuser' attempts to delete the user 'newuser' with verbose output, which will fail with an error if the user does not exist, and it is a destructive command that should not be used for mere existence checks.

42
Multi-Selecthard

Which THREE of the following statements about the user private group (UPG) scheme are true?

Select 3 answers
A.It is the default scheme in Red Hat-based distributions.
B.The umask 0027 ensures files created are NOT readable by the group.
C.The primary group of a user is a system group with GID less than 1000.
D.It ensures that new files have a default group of the user's private group.
E.Each user is assigned a unique group with the same name as the username.
AnswersA, D, E

Red Hat-based distributions like RHEL, CentOS, and Fedora use User Private Groups (UPG) by default, where each user is assigned a unique private group with the same name as the username.

Why this answer

Options A, D, and E are true. A: It is the default scheme in Red Hat-based distributions. D: It ensures that new files have a default group of the user's private group.

E: Each user is assigned a unique group with the same name as the username. B is false because umask 0027 gives group read permission, not denies it. C is false because the primary group is the user's private group, not a system group.

Ready to test yourself?

Try a timed practice session using only User and Group Management questions.