EX200 Manage users and groups Practice Question
A system administrator needs to ensure that the user 'jdoe' cannot log in via SSH but can still use other services like FTP. Which approach should the administrator take?
⚠ Common exam trap
A common mix-up: candidates confuse account locking (usermod -L) with shell restriction, assuming that locking the account only affects SSH, when in fact it blocks all password-based authentication, including FTP and other services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the user's shell to /sbin/nologin
Changing the user's shell to /sbin/nologin prevents interactive login via SSH (which requires a valid shell listed in /etc/shells) while still allowing non-interactive services like FTP, which typically do not check the user's shell. This approach specifically blocks SSH access without locking the account or affecting other authentication methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lock the user account with 'usermod -L jdoe'
Why it's wrong here
usermod -L jdoe prepends an exclamation mark to the encrypted password in /etc/shadow, disabling password-based authentication for every PAM-aware service, including FTP, SSH password login, and console login. This blocks the very FTP access the administrator wants to preserve, making it too broad a restriction for the desired outcome. The command does not merely stop interactive shells; it stops all credential validation, so it is the wrong tool here.
- ✗
Delete the user's password with 'passwd -d jdoe'
Why it's wrong here
passwd -d jdoe erases the password hash, leaving an empty password field. By default, PAM and most FTP servers treat an empty password as invalid and reject the authentication attempt entirely, so FTP login would fail; if the system has nullok enabled, it would allow passwordless login, which is a serious security vulnerability. Neither outcome meets the requirement of continuing to allow FTP while blocking interactive shell, and removing the password may also disable other account checks.
- ✗
Remove the user's home directory
Why it's wrong here
Deleting the home directory with something like rm -rf /home/jdoe has no effect on the account's authentication state because login validation uses /etc/passwd, /etc/shadow, and PAM, not the home directory. The user will still be able to log in via SSH or the console and will simply be placed in an empty or non-existent home directory, potentially causing application errors but not preventing shell access. FTP would also remain available, so this action fails to restrict the interactive login the admin needs to block.
- ✓
Change the user's shell to /sbin/nologin
Why this is correct
Setting jdoe's shell to /sbin/nologin in /etc/passwd makes PAM deny interactive login sessions, typically printing 'This account is currently not available.' FTP daemons such as vsftpd or proftpd authenticate against /etc/shadow without invoking the user's shell, so they still allow file transfers. Because /sbin/nologin only blocks shell access and does not alter the password hash, it is the standard, targeted solution for allowing non-login services while prohibiting interactive logins.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.