EX200 Manage security Practice Question
Which TWO statements about the /etc/shadow file are true? (Select exactly two.)
⚠ Common exam trap
A common pitfall on Red Hat exams is confusing /etc/passwd (which contains UIDs and is world-readable) with /etc/shadow (which contains hashed passwords and is root-only). Many candidates incorrectly think /etc/shadow contains UIDs or is readable by all users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contains hashed passwords for local users.
The /etc/shadow file stores hashed user passwords using algorithms like SHA-512 or yescrypt, as defined by the pam_unix module. It also contains password aging fields (e.g., minimum days, maximum days, warning period) that enforce password expiration policies. These two functions make options A and E correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Contains hashed passwords for local users.
Why this is correct
This file is the central repository for each local user's password hash, stored as a salted string using an algorithm identifier such as $6$ for SHA-512 or $y$ for yescrypt. Because /etc/passwd must be world-readable for tools like ls -l to map UIDs, the encrypted password field there was moved out to this protected file. The presence of a password hash here is what makes local login authentication possible; an x field in /etc/passwd simply indicates the hash is in /etc/shadow.
- ✗
Contains the user's UID.
Why it's wrong here
User IDs (UIDs) are assigned and recorded in /etc/passwd as its third colon-separated field, not in /etc/shadow. The /etc/shadow file's fields start with the login name and then proceed directly to the password hash and aging parameters such as last change date and maximum days. While the shadow file does reference the matching passwd entry by username, it never stores the numeric UID itself, making this statement factually incorrect.
- ✗
Is used to store encrypted group passwords.
Why it's wrong here
Group password hashes, when they exist, are stored in /etc/gshadow rather than /etc/shadow. The /etc/shadow file exclusively handles local user account password data, whereas group-level security credentials and administrative information for groups are placed in the corresponding gshadow file. Encrypting group passwords is a separate feature that relies on a completely different file with its own permissions, so this option misattributes a function designed for group management.
- ✗
Is readable by all users.
Why it's wrong here
To protect password hashes from offline cracking attempts, /etc/shadow is not accessible to ordinary users; typical permissions are 0000 or 0640 owned by root:shadow. Only the root user and processes running with the shadow group (such as certain password management tools) can read it. In contrast, /etc/passwd is intentionally world-readable so that every process can look up UIDs and usernames without exposing the secret hashes that reside in the shadow file.
- ✓
Contains password aging information such as minimum and maximum days.
Why this is correct
Beyond the hash itself, each shadow entry includes aging fields that enforce and audit password policies: the day of last change, minimum days before a change is allowed, maximum days of validity, warning period before expiration, and an inactivity window after expiry. These numeric day-based fields are what allow system administrators to implement mandatory rotation and account locking via commands like chage -M. Without these aging fields, an administrator could only force a password reset manually, so this data is essential to modern aging policy.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.