Select the THREE statements that correctly describe /etc/shadow on a typical Linux system.

LPIC-1 Exam 102-500, objective 107. Administrative tasks hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Choose 3.

Correct The first field is the login name, the same name used in /etc/passwd.

Correct. The login name is the key that joins the two files; /etc/shadow does not repeat the UID.

Correct The file is readable only by root (and typically the shadow group), unlike /etc/passwd which is world readable.

Correct. That restriction is the whole point of shadow passwords: the hashes are moved out of the world-readable /etc/passwd so they cannot be harvested for offline cracking.

Not correct The user's login shell is stored in the last field.

Wrong. The login shell is the seventh and last field of /etc/passwd. The last field of /etc/shadow is reserved for future use and is normally empty.

Not correct The user's numeric UID is stored in the second field.

Wrong. The second field is the hashed password. A value of ! or !! or * there means no password-based login is possible. The UID lives in /etc/passwd only.

Correct The third field records the date of the last password change as a number of days since 1970-01-01.

Correct. It is a day count, not a formatted date. A value of 0 has the special meaning that the user must change the password at next login.

Why

/etc/shadow fields in order: login name, hashed password, last change (days since epoch), minimum days, maximum days, warning days, inactive days, account expiry date (days since epoch), reserved. /etc/passwd fields in order: login name, password placeholder x, UID, GID, GECOS comment, home directory, login shell.

Where this comes from

Cited
LPI exam objective 107.1
What it says
Know the format and meaning of the fields in /etc/passwd and /etc/shadow.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Administrative tasks

Practise LPIC-1 Exam 102-500