EX200 Operate running systems Practice Question
A security policy requires user passwords to expire 60 days after last change. Which command sets this for user 'jdoe'?
⚠ Common exam trap
Candidates often confuse the `-m` and `-M` flags in `chage`, where candidates often mistakenly think `-m` sets the maximum age (expiration) when it actually sets the minimum days between changes, or they incorrectly recall `usermod -f` as the password expiration command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chage -M 60 jdoe
The `chage -M 60 jdoe` command sets the maximum number of days a password is valid for user 'jdoe' to 60 days. The `-M` flag in `chage` directly controls the password expiration period, counting from the last password change, which matches the security policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
usermod -f 60 jdoe
Why it's wrong here
usermod -f 60 jdoe alters the INACTIVE field in /etc/shadow, defining how many days after a password has already expired the account is disabled. It does not set the password lifetime itself, so a user whose password never expires would never reach the inactivity grace period. To enforce a 60-day expiration, the MAX_DAYS field must be set, which is exactly what chage -M 60 jdoe does.
- ✗
passwd -x 60 jdoe
Why it's wrong here
The passwd -x 60 jdoe command does write the maximum password age (MAX_DAYS) to /etc/shadow, but it is a legacy interface that is not recommended for managing password aging policy. The EX200 exam expects chage because it provides a consistent, scriptable way to view and modify the full set of aging fields (-m, -M, -W, -I), whereas passwd mixes account maintenance with policy changes. Using chage -M 60 jdoe is the correct, unambiguous method to satisfy the requirement.
- ✗
chage -m 60 jdoe
Why it's wrong here
chage -m 60 jdoe sets the MIN_DAYS field in /etc/shadow, which is the minimum number of days that must pass before a user is allowed to change their password again. This is a password-history control designed to prevent users from cycling back to an old password immediately, not a lifetime limit. The security policy demands that passwords stop working after 60 days, so the correct field is MAX_DAYS, set with chage -M 60 jdoe.
- ✓
chage -M 60 jdoe
Why this is correct
chage -M 60 jdoe sets the MAX_DAYS field in /etc/shadow, which defines the maximum number of days a password is valid before the system forces the user to choose a new one. With this command, jdoe's password will expire 60 days after the most recent password change, directly implementing the security policy. chage is the standard utility for password aging because it lets an administrator read and write the aging fields clearly and predictably.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.