Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age?

LPIC-1 Exam 102-500, objective 107. Administrative tasks medium

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Not correct chage -m 90 carol

Wrong. Lowercase -m sets the MINIMUM number of days between password changes. Setting it to 90 would forbid carol from changing her password again for 90 days, which is close to the opposite of the intent.

Not correct chage -W 90 carol

Wrong. -W sets the warning period: how many days before expiry the user starts being warned at login. It does not expire anything.

Not correct chage -E 90 carol

Wrong. -E sets an account expiry DATE, after which the account itself is disabled entirely. It takes a date (or days since 1970-01-01), not a password lifetime.

Correct chage -M 90 carol

Correct. Uppercase -M sets the maximum number of days a password remains valid. After 90 days carol is forced to choose a new one at login.

Why

chage edits the aging fields of /etc/shadow: -m minimum days, -M maximum days, -W warning days, -I inactive days after expiry, -E account expiry date, -d last change date. `chage -l carol` prints all of them in readable form. The defaults for newly created accounts come from PASS_MIN_DAYS, PASS_MAX_DAYS and PASS_WARN_AGE in /etc/login.defs.

Where this comes from

Cited
LPI exam objective 107.1
What it says
Manage password aging information for accounts.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 107 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500