EX200 Manage security Practice Question
Which command checks if a user's password has expired and forces a password change at next login?
⚠ Common exam trap
The trick is to distinguish between password expiration (chage -d 0) and account locking (passwd -l, usermod -L). Many candidates incorrectly choose an account lock command because they think it forces a password change at next login, but locking prevents login entirely until unlocked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chage -d 0 username
The `chage -d 0 username` command sets the last password change date to the epoch (January 1, 1970), which forces the password to be considered expired immediately. On the next login, the system will prompt the user to change their password before granting access, as defined by the PAM (Pluggable Authentication Modules) password aging policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
chage -d 0 username
Why this is correct
chage -d 0 sets the 'date of last password change' field to 0, representing the epoch date (1970-01-01). When the user attempts to log in, the system compares the current date to this zero epoch and determines that the password has already exceeded its maximum age, forcing an immediate password change. This command is the standard method to expire a user's existing password without locking the account or requiring manual intervention.
- ✗
passwd -f username
Why it's wrong here
passwd -f is not a valid option on Red Hat Enterprise Linux; the passwd command supports -d, -l, -u, -S, -e, -x, -n, -w, and -i, but there is no -f flag. If you run this command, you will simply receive a usage error, and it will have no effect on the password or its expiration status. The correct passwd option to force password expiration is -e, which sets the last password change date to the epoch, equivalent to chage -d 0.
- ✗
usermod -L username
Why it's wrong here
usermod -L prepends a '!' to the user's password hash in /etc/shadow, which immediately locks the account and prevents login using the password. This operation does not modify the password aging fields (last change, max days, or warning period), so the password itself is not expired; it is merely disabled. After an administrator unlocks the account with usermod -U, the user can still log in with the old, unexpired password, demonstrating that this command is a lockout tool, not an expiration mechanism.
- ✗
passwd -l username
Why it's wrong here
passwd -l also adds a '!' to the beginning of the user's encrypted password in /etc/shadow, disabling password-based authentication entirely. Unlike chage -d 0, this command does not alter the last-change date or any aging parameters, so it neither checks nor forces password expiration; it is purely an administrative lockout operation. To force a password change using passwd, the correct flag is -e (expire), which is functionally identical to setting the last password change to the epoch date, not -l.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.