Select the THREE statements that correctly describe /etc/shadow on a typical Linux system.
LPIC-1 Exam 102-500, objective 107. Administrative tasks hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Choose 3.
Correct The first field is the login name, the same name used in /etc/passwd.
Correct. The login name is the key that joins the two files; /etc/shadow does not repeat the UID.
Correct The file is readable only by root (and typically the shadow group), unlike /etc/passwd which is world readable.
Correct. That restriction is the whole point of shadow passwords: the hashes are moved out of the world-readable /etc/passwd so they cannot be harvested for offline cracking.
Not correct The user's login shell is stored in the last field.
Wrong. The login shell is the seventh and last field of /etc/passwd. The last field of /etc/shadow is reserved for future use and is normally empty.
Not correct The user's numeric UID is stored in the second field.
Wrong. The second field is the hashed password. A value of ! or !! or * there means no password-based login is possible. The UID lives in /etc/passwd only.
Correct The third field records the date of the last password change as a number of days since 1970-01-01.
Correct. It is a day count, not a formatted date. A value of 0 has the special meaning that the user must change the password at next login.
Why
/etc/shadow fields in order: login name, hashed password, last change (days since epoch), minimum days, maximum days, warning days, inactive days, account expiry date (days since epoch), reserved. /etc/passwd fields in order: login name, password placeholder x, UID, GID, GECOS comment, home directory, login shell.
Where this comes from
- Cited
- LPI exam objective 107.1
- What it says
- Know the format and meaning of the fields in /etc/passwd and /etc/shadow.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked