EX200 Deploy, configure, and maintain systems Practice Question
A user reports that they cannot log in to a RHEL 9 system. The administrator checks /etc/passwd and finds the user's shell is set to /sbin/nologin. What is the most likely cause?
⚠ Common exam trap
Many exam-takers confuse the /sbin/nologin shell with account locking or password expiration, not realizing that the shell setting is a deliberate, static configuration to disable interactive login without affecting password state or authentication attempts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user account is intentionally disabled for login.
The /sbin/nologin shell is a valid shell entry that, when set as a user's login shell, prevents interactive login by immediately exiting with a message that the account is not available. This is a standard method for disabling login for system accounts (e.g., daemon, bin) or intentionally disabling a user account while keeping the account and its files intact. Option D correctly identifies that the user account is intentionally disabled for login.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SSH service is not running.
Why it's wrong here
If sshd is not running, no user can access the system via SSH, but a single user reporting a login problem suggests a user-specific issue. The SSH service is a system-wide resource; its failure would affect all remote users simultaneously, not just one account. Furthermore, if the user is attempting a local console login, SSH is irrelevant entirely. Therefore, this cannot explain a single user's inability to log in.
- ✗
The user account has been locked by pam_tally2.
Why it's wrong here
pam_tally2 is deprecated in RHEL 9, replaced by pam_faillock, and it locks an account only after a specific number of failed authentication attempts. A lockout from pam_tally2 would produce a distinct message, such as 'Account locked due to N failed logins,' and would be visible via the faillock command or in /etc/shadow with a lock indicator. The user's issue is that the account is intentionally disabled, which is a different administrative state not caused by failed attempts. Thus, this is not the correct diagnosis.
- ✗
The user's password has expired.
Why it's wrong here
Password expiration is controlled by the chage policy and is stored in the expiration fields of /etc/shadow. When a password has expired, the user is not outright denied login; instead, the system forces an interactive password change before allowing access. Only an expired account (account expiration, not password expiration) would completely block authentication, and that is represented by a different shadow field. The user's inability to log in is due to an intentional account disablement, not a password aging issue.
- ✓
The user account is intentionally disabled for login.
Why this is correct
An intentionally disabled login account is typically configured with /sbin/nologin as the user's login shell or by locking the account in /etc/shadow with an '!' or '*' in the encrypted password field. This prevents the user from starting an interactive shell while still potentially allowing non-login services like POP3 or FTP, depending on PAM configuration. Because the problem is isolated to one user and no other users are affected, an administrative disablement is the most precise cause. The system administrator can verify this with the 'chsh -l' or by inspecting the last field of /etc/passwd.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.