LFCS User and Group Management Practice Question
Which two commands can be used to set password expiration policies for a user?
⚠ Common exam trap
Test-takers frequently confuse `usermod` with `chage` because `usermod` can lock accounts, but it cannot set password aging parameters like maximum days or warning periods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
passwd
The `passwd` command (option B) can set password expiration policies for a user via options such as `-e` (expire immediately), `-n` (minimum days), `-x` (maximum days), `-w` (warning days), and `-i` (inactive days), e.g., `passwd -x 90 -n 7 -w 14 user`. The `chage` command (option C) is specifically designed to modify password aging information in `/etc/shadow`, using flags like `-M` (max days), `-m` (min days), `-W` (warn days), `-I` (inactive days), and `-E` (account expiration date), e.g., `chage -M 90 -W 14 user`. The other options do not belong: `usermod` (A) manages account properties like groups, shell, and home directory but does not set password aging fields; `expiry` (D) is not a standard Linux command for this purpose; and `pwconv` (E) creates or updates `/etc/shadow` from `/etc/passwd` rather than setting expiration policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
usermod
Why it's wrong here
usermod alone sets account and password expiry fields such as --expiredate and --inactive, but the question asks for two commands, and usermod cannot enforce maximum or minimum password age policy. It is tempting because usermod is the correct choice for locking accounts or setting a single expiry date.
- ✓
passwd
Why this is correct
The passwd command, via its -e, -n, -x, -w and -i options, sets password expiration fields such as maximum age, minimum age and warning period for a user. This satisfies the requirement for a command that configures password expiration policy.
- ✓
chage
Why this is correct
chage edits the shadow password ageing fields, including maximum days, minimum days, warning period and account expiry, for a specified user. It directly satisfies the requirement to set password expiration policy, unlike passwd, which only changes the password itself.
- ✗
expiry
Why it's wrong here
There is no Linux command named expiry; it is not a valid utility for setting account or password aging. The name resembles chage, which does manage password expiration. A tool with that name would be the right choice if the task were checking or modifying aging information interactively.
- ✗
pwconv
Why it's wrong here
pwconv converts passwd entries into shadow format; it does not set expiration policy. It is the correct tool when migrating an unshadowed system to shadow passwords, whereas aging values such as maximum days and warning periods are configured through chage.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.