EX200 · domain
Manage users and groups
This domain covers local account and group administration on RHEL using useradd, usermod, groupadd, passwd, chage, and the /etc/passwd, /etc/shadow, and /etc/group files. Questions are hands-on: you add users, set supplementary groups, manage password aging, and verify effective group membership after re-login.
Focused practice
Practice Manage users and groups questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Manage users and groups
Be able to add and modify local users and groups, append supplementary groups with usermod -aG, configure password aging via chage, and confirm effective membership with id or groups. The critical detail: always use -a with -G, and re-login for group changes to apply.
Using usermod -aG to append supplementary groups without dropping existing ones
Editing /etc/shadow fields with chage for password aging and inactivity lockout
Verifying effective group membership with the id and groups commands
Creating users and groups with useradd, groupadd, and setting passwords with passwd
Watch out for
Common Manage users and groups exam traps
- ▸Running usermod -G without -a, which replaces all existing supplementary groups instead of appending the new ones.
- ▸Assuming group changes apply to the current session; membership only takes effect after logout and login.
- ▸Confusing the /etc/shadow inactivity field with account expiration, or miscounting the colon-separated fields.
Question index
All Manage users and groups questions (37)
Click any question to see the full explanation, or start a practice session above.
Which TWO commands can change the primary group of an existing user?
Medium2An administrator needs to create a user account that will be used by an application service. The account should not have a valid shell or home directory. Which command correctly creates such an account?
Medium3Refer to the exhibit. A user named 'carol' has been added to the system with the command useradd -G wheel carol. Which line in /etc/group will confirm that carol is now a member of the wheel group?
Medium4Which TWO commands can list all groups a user belongs to? (Choose exactly 2)
Easy5An administrator is migrating user accounts to a new system. They want to preserve the user's primary group name and GID. Which commands should be used in sequence?
Hard6A system administrator needs to change the primary group of an existing user to a group that already exists. Which command should be used?
Medium7A junior administrator is asked to create a new group named 'qa' with an explicit GID of 4500 on a Red Hat Enterprise Linux 8 server. After running the appropriate command, they verify the result with getent group qa and see 'qa:x:4500:'. Which command did the junior administrator most likely run?
Medium8A system administrator needs to ensure that a user named 'jdoe' can execute commands as root without being prompted for a password. Which configuration change should be made?
Medium9A user named jdoe is receiving 'Permission denied' errors when trying to access a file owned by root with permissions 644. The user is a member of the root group. What is the most likely cause?
Medium10A server has a requirement that all users in the 'finance' group must have a password aging policy that forces password change every 90 days. Which approach best achieves this for existing users?
Hard11A user reports they cannot log in to a Linux system. Their account was recently created. The administrator checks /etc/passwd and sees the entry: jsmith:x:1001:1001::/home/jsmith:/sbin/nologin. What is the likely issue?
Easy12Refer to the exhibit. What effect does the value INACTIVE=-1 have on newly created user accounts?
Hard13A user jdoe, who is a member of the group staff, reports they cannot access the directory /shared. The administrator runs getfacl /shared and receives the output shown. Which of the following explains the issue?
Medium14An administrator accidentally deleted the group 'sales' which is the primary group of several users. What is the immediate effect on those users?
Hard15Which TWO commands can be used to add a user to an existing supplementary group without removing them from other groups?
Easy16A Red Hat Enterprise Linux 9 system enforces a security policy that user accounts must be disabled after 90 days of inactivity. The system administrator has configured /etc/shadow accordingly with the proper fields. User 'bob' has been on leave for 95 days. When bob returns and tries to log in, he is unable to do so. The administrator checks the shadow file and sees that bob's password expiration date has passed and the account is locked due to inactivity (the inactivity period has exceeded). The administrator wants to immediately reactivate bob's account without changing the password, and also wants to set the account to expire in 30 days from now (relative to the current date). Which set of commands should the administrator run to achieve this goal?
Hard17You are managing a Red Hat Enterprise Linux 8 server that hosts backup scripts. A user named 'backup' (UID 1005) is a member of the 'backup' group. The directory /var/backups is owned by root:backup with permissions 775. The 'backup' user needs to create files in this directory. However, when the user attempts to create a file, they receive 'Permission denied'. You verify that 'backup' is indeed listed in the backup group in /etc/group. The user's current shell was started after their last login. Which of the following is the most likely cause and solution?
Hard18A system administrator needs to ensure that a user named 'bob' can access a shared directory '/data' owned by group 'developers'. The directory has permissions 2775 and is owned by root:developers. Bob is a member of the 'developers' group. However, when Bob tries to create a file in '/data', it fails with 'Permission denied'. What is the most likely cause?
Hard19Alice tries to run 'sudo less /var/log/messages' and gets 'Sorry, user alice is not allowed to execute /usr/bin/less /var/log/messages as root on this host.' Why?
Hard20An administrator wants to ensure that any new user accounts created on the system have a default primary group matching the username. What change is needed?
Medium21Which TWO commands can be used to create a new user account in Red Hat Enterprise Linux 8?
Easy22A helpdesk ticket states that user 'bob' cannot write to his own home directory. The directory /home/bob has permissions drwxr-xr-x and is owned by root:root. What command will fix this?
Easy23A company policy requires that when a user is deleted, all files owned by that user in /home should be reassigned to a 'guest' account. Which command accomplishes this?
Medium24Which TWO commands can be used to add a user to a secondary group without removing existing supplementary group memberships? (Choose exactly 2)
Medium25A system administrator needs to ensure that the user 'jdoe' can read files in the shared directory /project/data which is owned by group 'project'. The user 'jdoe' is currently not a member of the 'project' group. Which TWO steps should the administrator take to add 'jdoe' to the 'project' group? (Choose two.)
Medium26A new employee named asmith needs a user account with a home directory and a specific UID of 1500. Which command accomplishes this?
Easy27A company needs to create a user account for a temporary contractor who will work for exactly 90 days. The account must be automatically disabled after 90 days. Which command should the administrator use?
Easy28After being added to a new supplementary group with usermod -aG, a user logs out and back in but still cannot access files owned by that group. Which command should the user run to verify current effective group membership?
Hard29Match each firewall zone to its default trust level.
Medium30A user was recently added to the 'testgrp' group using `usermod -aG testgrp user1`. However, when they try to access a file owned by testgrp with permissions 660, they get permission denied. What is the most likely reason?
Medium31Arrange the steps to configure a network bond (mode 1) using two interfaces (eth0, eth1) in RHEL.
Medium32An administrator wants to modify the default expiration settings for new user passwords. Which file should be modified?
Easy33Which THREE statements about /etc/shadow are true? (Choose exactly 3)
Hard34A system administrator needs to ensure that the user 'jdoe' cannot log in via SSH but can still use other services like FTP. Which approach should the administrator take?
Easy35A server has been compromised, and the administrator suspects an unauthorized user account may have been created. Which file should be examined to list all local user accounts?
Easy36An administrator used the command useradd -D -f 10 to change the default inactivity period. What effect does this have on future user accounts?
Hard37An administrator wants to add the user 'jane' to the supplementary groups 'wheel' and 'docker' without removing her from other groups. Which command should be used?
EasyOther domains
All EX200 exam domains
Frequently asked questions
- What does the Manage users and groups domain cover on the EX200 exam?
- Be able to add and modify local users and groups, append supplementary groups with usermod -aG, configure password aging via chage, and confirm effective membership with id or groups. The critical detail: always use -a with -G, and re-login for group changes to apply.
- How many questions are in this domain?
- This page lists all 37 Manage users and groups questions in the EX200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Manage users and groups questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.