Courseiva

LFCS User and Group Management Practice Question

Which two commands can be used to set password expiration policies for a user?

⚠ Common exam trap

Test-takers frequently confuse `usermod` with `chage` because `usermod` can lock accounts, but it cannot set password aging parameters like maximum days or warning periods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

passwd

The `passwd` command (option B) can set password expiration policies for a user via options such as `-e` (expire immediately), `-n` (minimum days), `-x` (maximum days), `-w` (warning days), and `-i` (inactive days), e.g., `passwd -x 90 -n 7 -w 14 user`. The `chage` command (option C) is specifically designed to modify password aging information in `/etc/shadow`, using flags like `-M` (max days), `-m` (min days), `-W` (warn days), `-I` (inactive days), and `-E` (account expiration date), e.g., `chage -M 90 -W 14 user`. The other options do not belong: `usermod` (A) manages account properties like groups, shell, and home directory but does not set password aging fields; `expiry` (D) is not a standard Linux command for this purpose; and `pwconv` (E) creates or updates `/etc/shadow` from `/etc/passwd` rather than setting expiration policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    usermod

    Why it's wrong here

    usermod alone sets account and password expiry fields such as --expiredate and --inactive, but the question asks for two commands, and usermod cannot enforce maximum or minimum password age policy. It is tempting because usermod is the correct choice for locking accounts or setting a single expiry date.

  • ✓

    passwd

    Why this is correct

    The passwd command, via its -e, -n, -x, -w and -i options, sets password expiration fields such as maximum age, minimum age and warning period for a user. This satisfies the requirement for a command that configures password expiration policy.

  • ✓

    chage

    Why this is correct

    chage edits the shadow password ageing fields, including maximum days, minimum days, warning period and account expiry, for a specified user. It directly satisfies the requirement to set password expiration policy, unlike passwd, which only changes the password itself.

  • ✗

    expiry

    Why it's wrong here

    There is no Linux command named expiry; it is not a valid utility for setting account or password aging. The name resembles chage, which does manage password expiration. A tool with that name would be the right choice if the task were checking or modifying aging information interactively.

  • ✗

    pwconv

    Why it's wrong here

    pwconv converts passwd entries into shadow format; it does not set expiration policy. It is the correct tool when migrating an unshadowed system to shadow passwords, whereas aging values such as maximum days and warning periods are configured through chage.

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.