Courseiva
Manage security →easyMultiple Choice

Prevent User Login via SSH or Console: Using /sbin/nologin

A junior admin needs to ensure that the 'apache' user (UID 48) cannot log in via SSH or console. Which command achieves this?

Quick Answer

The answer is `usermod -s /sbin/nologin apache`. This command works by changing the user’s login shell to `/sbin/nologin`, a special program that prints a polite message and immediately exits, preventing the user from obtaining any interactive shell via SSH or console login. The key technical concept is that the system executes the user’s configured shell at login; by setting it to `/sbin/nologin`, you deny shell access while leaving the apache user’s other services—like the web server—fully functional. On the Red Hat Certified System Administrator EX200 exam, this tests your understanding of user account security and the `/etc/passwd` shell field. A common trap is confusing `nologin` with locking the account via `usermod -L`, which only disables password-based login but still allows SSH key authentication; `nologin` blocks all interactive logins regardless of method. Remember the mnemonic: “No shell, no login—nologin is the shell that tells them to go away.”

⚠ Common exam trap

It's easy for candidates to confuse password locking (`passwd -l`) with shell restriction, not realizing that SSH key authentication or console login via `su` bypasses password locks, while changing the shell to `/sbin/nologin` blocks all interactive login methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

usermod -s /sbin/nologin apache

Setting the user's login shell to `/sbin/nologin` prevents the user from obtaining an interactive shell via SSH or console login. When the user attempts to log in, the system executes `/sbin/nologin`, which prints a polite message and exits immediately, effectively denying shell access while leaving other services (e.g., Apache) functional.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    usermod -s /sbin/nologin apache

    Why this is correct

    Setting the login shell to /sbin/nologin blocks interactive SSH and console sessions for apache while leaving the account valid for service processes. This satisfies the requirement to deny login without deleting the UID 48 account.

  • ✗

    passwd -l apache

    Why it's wrong here

    Locking the password hash with passwd -l blocks password authentication only; SSH keys and console logins via other mechanisms still succeed, so the account remains usable. It is tempting because it is the standard tool for disabling password logins, and would be correct if the requirement were solely to prevent password-based access.

  • ✗

    chage -l apache

    Why it's wrong here

    chage -l only lists an account's password aging information; it changes nothing, so SSH and console logins remain possible. It is tempting because chage -E can expire an account, which would be correct if the task were disabling logins by expiry rather than locking the account.

  • ✗

    usermod -e 1 apache

    Why it's wrong here

    Setting the account expiration date to 1 (early epoch) immediately expires the account, which does prevent login immediately. However, this is not the preferred method because it disables all logins (including non-interactive) and is not the standard way to disable interactive logins for a service account. The recommended approach is to change the shell to /sbin/nologin.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on EX200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE factors determine whether a local user can SSH into a Red Hat Enterprise Linux 9 system? (Choose three.)

hard
  • A.The /etc/nologin file exists.
  • B.The user has sudo privileges.
  • ✓ C.The user's shell is listed in /etc/shells.
  • ✓ D.The user's ~/.ssh/authorized_keys file exists and has correct permissions.
  • ✓ E.The /etc/ssh/sshd_config file allows password or key authentication.

Why C: SSHd validates that the user's login shell is listed in /etc/shells before allowing authentication. If the shell is not present in /etc/shells (e.g., /sbin/nologin or a custom script), SSHd will deny the connection, even if the user has valid credentials. This check is controlled by the 'AllowUsers' and 'DenyUsers' directives but is a fundamental security measure to prevent users with non-standard shells from gaining interactive access.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.