You must lock the password of the account bob so that he cannot authenticate with it, while leaving the account and its files in place. Select the TWO commands that achieve exactly that.
LPIC-1 Exam 102-500, objective 107. Administrative tasks medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Choose 2.
Not correct passwd -d bob
Wrong, and the opposite of safe. -d deletes the password, leaving the field empty. Depending on PAM configuration that can permit login with no password at all.
Correct usermod -L bob
Correct. -L locks the password by prefixing the stored hash in /etc/shadow with an exclamation mark, so no supplied password can ever hash to a match. usermod -U reverses it.
Not correct userdel bob
Wrong. This removes the account entirely from /etc/passwd, /etc/shadow and the group files. Nothing is left to unlock later.
Correct passwd -l bob
Correct. -l locks the account's password in the same way, by prefixing the hash so it cannot match. passwd -u unlocks it, and passwd -S reports the current state.
Not correct usermod -s /sbin/nologin bob
Wrong for this requirement. Changing the shell blocks interactive login sessions, but it does not lock the password, so services that authenticate against it without spawning a shell can still accept it.
Why
Locking works by making the stored hash unmatchable: the ! prefix means no input can ever hash to that string, while the original hash is preserved so unlocking restores the old password. Locking the password does not stop SSH public-key logins, which is why hardening an account often means locking the password AND setting a nologin shell.
Where this comes from
- Cited
- LPI exam objective 107.1
- What it says
- Lock and unlock user accounts and change passwords.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked