Select the THREE statements that correctly describe /etc/shadow on a typical Linux system.

LPIC-1 Exam 102-500, objective 107. Administrative tasks hard

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Choose 3.

Correct The first field is the login name, the same name used in /etc/passwd.

Correct. The login name is the key that joins the two files; /etc/shadow does not repeat the UID.

Correct The file is readable only by root (and typically the shadow group), unlike /etc/passwd which is world readable.

Correct. That restriction is the whole point of shadow passwords: the hashes are moved out of the world-readable /etc/passwd so they cannot be harvested for offline cracking.

Not correct The user's login shell is stored in the last field.

Wrong. The login shell is the seventh and last field of /etc/passwd. The last field of /etc/shadow is reserved for future use and is normally empty.

Not correct The user's numeric UID is stored in the second field.

Wrong. The second field is the hashed password. A value of ! or !! or * there means no password-based login is possible. The UID lives in /etc/passwd only.

Correct The third field records the date of the last password change as a number of days since 1970-01-01.

Correct. It is a day count, not a formatted date. A value of 0 has the special meaning that the user must change the password at next login.

Why

/etc/shadow fields in order: login name, hashed password, last change (days since epoch), minimum days, maximum days, warning days, inactive days, account expiry date (days since epoch), reserved. /etc/passwd fields in order: login name, password placeholder x, UID, GID, GECOS comment, home directory, login shell.

Where this comes from

Cited
LPI exam objective 107.1
What it says
Know the format and meaning of the fields in /etc/passwd and /etc/shadow.

Practise this

Reading one question is not practice. The trainer will draw a set from objective 107 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500