Courseiva
Operate running systems →easyMultiple Choice

EX200 Operate running systems Practice Question

A security policy requires user passwords to expire 60 days after last change. Which command sets this for user 'jdoe'?

⚠ Common exam trap

Candidates often confuse the `-m` and `-M` flags in `chage`, where candidates often mistakenly think `-m` sets the maximum age (expiration) when it actually sets the minimum days between changes, or they incorrectly recall `usermod -f` as the password expiration command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

chage -M 60 jdoe

The `chage -M 60 jdoe` command sets the maximum number of days a password is valid for user 'jdoe' to 60 days. The `-M` flag in `chage` directly controls the password expiration period, counting from the last password change, which matches the security policy requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    usermod -f 60 jdoe

    Why it's wrong here

    usermod -f 60 jdoe alters the INACTIVE field in /etc/shadow, defining how many days after a password has already expired the account is disabled. It does not set the password lifetime itself, so a user whose password never expires would never reach the inactivity grace period. To enforce a 60-day expiration, the MAX_DAYS field must be set, which is exactly what chage -M 60 jdoe does.

  • ✗

    passwd -x 60 jdoe

    Why it's wrong here

    The passwd -x 60 jdoe command does write the maximum password age (MAX_DAYS) to /etc/shadow, but it is a legacy interface that is not recommended for managing password aging policy. The EX200 exam expects chage because it provides a consistent, scriptable way to view and modify the full set of aging fields (-m, -M, -W, -I), whereas passwd mixes account maintenance with policy changes. Using chage -M 60 jdoe is the correct, unambiguous method to satisfy the requirement.

  • ✗

    chage -m 60 jdoe

    Why it's wrong here

    chage -m 60 jdoe sets the MIN_DAYS field in /etc/shadow, which is the minimum number of days that must pass before a user is allowed to change their password again. This is a password-history control designed to prevent users from cycling back to an old password immediately, not a lifetime limit. The security policy demands that passwords stop working after 60 days, so the correct field is MAX_DAYS, set with chage -M 60 jdoe.

  • ✓

    chage -M 60 jdoe

    Why this is correct

    chage -M 60 jdoe sets the MAX_DAYS field in /etc/shadow, which defines the maximum number of days a password is valid before the system forces the user to choose a new one. With this command, jdoe's password will expire 60 days after the most recent password change, directly implementing the security policy. chage is the standard utility for password aging because it lets an administrator read and write the aging fields clearly and predictably.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.