EX200 Manage users and groups Practice Question
Which TWO commands can list all groups a user belongs to? (Choose exactly 2)
⚠ Common exam trap
A common mix-up: candidates think `cat /etc/group | grep user` or `getent group user` will list all groups for a user, but these commands only search for a group named 'user' or lines containing the string, not the user's actual group memberships, which is a common misconception tested on the EX200 exam.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
id -nG
Option A, `id -nG`, is correct because it prints the names of all groups the specified user is a member of, including both the primary group and supplementary groups, using the `-n` flag to show names instead of numeric GIDs and `-G` to list all group memberships. Option E, `groups`, is correct because it displays the groups a user belongs to, defaulting to the current user or accepting a username argument, and it reads from the same system group database to show all memberships. Option B, `cat /etc/group | grep user`, is not reliable because it only matches the literal string 'user' in the group file and may miss memberships or match unintended entries, and it does not handle network-based group sources. Option C, `usermod -g user`, is incorrect because it modifies a user's primary group rather than listing group memberships. Option D, `getent group user`, is incorrect because it queries the group database for a group named 'user' and lists that group's members, not all groups a user belongs to.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
id -nG
Why this is correct
The `id -nG` command prints all group IDs for the named user (or the current user if no user is given) and then converts those numeric IDs to names via the `-n` flag. Because `id` queries the system's user and group databases through NSS, it includes the primary group from `/etc/passwd` and every supplementary group from `/etc/group` (or LDAP/SSSD), making it a complete and script-friendly listing.
- ✗
cat /etc/group | grep user
Why it's wrong here
Piping `cat /etc/group` through `grep` only finds lines that literally contain the username in the comma-separated member list, which is only true for supplementary group entries. The user's primary group is stored as a numeric GID in `/etc/passwd` and will not appear in `/etc/group` unless the user is also explicitly added there, so this approach silently omits the primary group. It also fails entirely when group information comes from NSS sources such as LDAP, where `/etc/group` is incomplete.
- ✗
usermod -g user
Why it's wrong here
`usermod -g` is a privileged account-modification command that changes the user's primary group; it does not list any group memberships. Running `usermod -g user` would attempt to set the primary group to a group named `user`, not to show which groups a user belongs to. This option misuses an administration tool that can modify `/etc/passwd` and requires root, and it produces no output of membership information.
- ✗
getent group user
Why it's wrong here
The `getent` command looks up individual database records, and `getent group user` treats `user` as a group name to be searched in the group database, not as a username. If a group named `user` does not exist, it returns nothing; if it does exist, it only shows that group's members, not the groups of the user. To list a user's groups with `getent`, you would need to iterate over all groups or use `id`, so this command does not answer the question.
- ✓
groups
Why this is correct
The `groups` command is the simplest way to display group memberships: without arguments it lists the current user's groups, and with a username argument it lists that user's groups. It prints both the primary group name and all supplementary group names in a single line, using the same NSS lookups as `id`. Note that `groups` is less easily parseable than `id -nG` for scripting, but it is a valid and direct answer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.