EX200 Manage security Practice Question
To enforce that user passwords expire every 90 days and users are warned 7 days before expiration, which command sets these policies for user 'john'?
⚠ Common exam trap
A common pitfall is confusing the `-m` (minimum days) with `-M` (maximum days) flag in `chage`. The RHCSA exam tests this distinction, and candidates may incorrectly select `usermod` or `passwd` for password expiration settings. Only `chage -M` sets the maximum password age, and `-W` sets the warning period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chage -M 90 -W 7 john
The `chage -M 90 -W 7 john` command sets the maximum number of days a password is valid (password aging) to 90 days via the `-M` flag, and the `-W` flag sets the warning period to 7 days before expiration. The `chage` command is the standard tool in Red Hat Enterprise Linux for modifying user password aging information stored in `/etc/shadow`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
chage -m 90 -W 7 john
Why it's wrong here
The -m flag sets minimum days between password changes, not maximum validity, so 90 here means users cannot change passwords for 90 days rather than expiring them. chage is the right tool, but -M 90 is the flag that enforces the 90-day expiry.
- ✓
chage -M 90 -W 7 john
Why this is correct
The chage command manages password aging in /etc/shadow. The -M 90 flag sets maximum days before expiry, while -W 7 defines the warning period before that expiry, together enforcing the 90-day rotation and 7-day advance notice for john.
- ✗
usermod -e 90 -f 7 john
Why it's wrong here
usermod -e sets the account expiration date and -f the inactivity days after expiry, neither of which controls password ageing. It is tempting because usermod manages user accounts, but password expiry and warning periods belong to chage, which the stem requires.
- ✗
passwd -x 90 -w 7 john
Why it's wrong here
The -x flag sets maximum password validity days, but -w sets the warning period, so -w 7 is correct here; however passwd lacks a flag for the minimum interval, and the stem's 90-day expiry maps to chage's -M, not -x. passwd suits quick per-user ageing tweaks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.