Courseiva
Manage users and groups →easyMultiple Choice

EX200 Manage users and groups Practice Question

A system administrator needs to ensure that the user 'jdoe' cannot log in via SSH but can still use other services like FTP. Which approach should the administrator take?

⚠ Common exam trap

A common mix-up: candidates confuse account locking (usermod -L) with shell restriction, assuming that locking the account only affects SSH, when in fact it blocks all password-based authentication, including FTP and other services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the user's shell to /sbin/nologin

Changing the user's shell to /sbin/nologin prevents interactive login via SSH (which requires a valid shell listed in /etc/shells) while still allowing non-interactive services like FTP, which typically do not check the user's shell. This approach specifically blocks SSH access without locking the account or affecting other authentication methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Lock the user account with 'usermod -L jdoe'

    Why it's wrong here

    usermod -L jdoe prepends an exclamation mark to the encrypted password in /etc/shadow, disabling password-based authentication for every PAM-aware service, including FTP, SSH password login, and console login. This blocks the very FTP access the administrator wants to preserve, making it too broad a restriction for the desired outcome. The command does not merely stop interactive shells; it stops all credential validation, so it is the wrong tool here.

  • ✗

    Delete the user's password with 'passwd -d jdoe'

    Why it's wrong here

    passwd -d jdoe erases the password hash, leaving an empty password field. By default, PAM and most FTP servers treat an empty password as invalid and reject the authentication attempt entirely, so FTP login would fail; if the system has nullok enabled, it would allow passwordless login, which is a serious security vulnerability. Neither outcome meets the requirement of continuing to allow FTP while blocking interactive shell, and removing the password may also disable other account checks.

  • ✗

    Remove the user's home directory

    Why it's wrong here

    Deleting the home directory with something like rm -rf /home/jdoe has no effect on the account's authentication state because login validation uses /etc/passwd, /etc/shadow, and PAM, not the home directory. The user will still be able to log in via SSH or the console and will simply be placed in an empty or non-existent home directory, potentially causing application errors but not preventing shell access. FTP would also remain available, so this action fails to restrict the interactive login the admin needs to block.

  • ✓

    Change the user's shell to /sbin/nologin

    Why this is correct

    Setting jdoe's shell to /sbin/nologin in /etc/passwd makes PAM deny interactive login sessions, typically printing 'This account is currently not available.' FTP daemons such as vsftpd or proftpd authenticate against /etc/shadow without invoking the user's shell, so they still allow file transfers. Because /sbin/nologin only blocks shell access and does not alter the password hash, it is the standard, targeted solution for allowing non-login services while prohibiting interactive logins.

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.