EX200 Manage users and groups Practice Question
An administrator used the command useradd -D -f 10 to change the default inactivity period. What effect does this have on future user accounts?
⚠ Common exam trap
Many exam-takers confuse the `-f` (inactivity period after password expiration) with password aging (`-M` or `PASS_MAX_DAYS`), leading candidates to incorrectly select options B or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
New user accounts will be disabled after 10 days of inactivity if the password has expired.
The `useradd -D -f 10` command modifies the default value for the `INACTIVE` field in `/etc/default/useradd`. This field sets the number of days after a password expires that the account will be disabled if the password is not changed. Option C correctly describes this behavior: new user accounts will be disabled after 10 days of inactivity following password expiration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The default group for new users will be changed to GID 10.
Why it's wrong here
The -f option of useradd does not modify group membership or GID defaults; it sets the inactivity period for accounts after password expiration. Default group configuration is controlled by -g, -G, or the GROUP variable in /etc/default/useradd, not the -f flag. GID 10 is likewise unrelated to inactivity settings.
- ✗
New user accounts will have a maximum password age of 10 days.
Why it's wrong here
Maximum password age is an attribute set via -M or -K PASS_MAX_DAYS on useradd, or through /etc/login.defs, and it defines how long a password remains valid before the user must change it. The -f flag governs what happens after that password already expired, specifically the grace period before account deactivation. Therefore, -f 10 does not impose a 10-day password lifetime.
- ✓
New user accounts will be disabled after 10 days of inactivity if the password has expired.
Why this is correct
The -f 10 option sets the INACTIVE field in /etc/default/useradd, which becomes the seventh field in the /etc/shadow entry, specifying how many days after a password expires the account is disabled. If the password never expires or is changed before that, inactivity does not apply; only after expiry does the 10-day countdown begin. When the countdown ends, the account is locked, preventing login until an administrator reactivates it.
- ✗
New user accounts will have a password expiration of 10 days.
Why it's wrong here
Setting a password expiration of 10 days would mean the user must choose a new password every 10 days, which is handled by the -M or -E option (or PASS_MAX_DAYS in /etc/login.defs), not -f. Password expiration dictates when the credential becomes invalid, whereas -f dictates the post-expiration inactivity window. Mixing these up is a common administrative error that leaves accounts suspended or never suspended depending on the real password-aging policies.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.