A daemon you are packaging must run under its own unprivileged account. The account should never be logged into, should not appear in the graphical login list, and should take a UID from the range reserved for system accounts. Which useradd option expresses that intent?
LPIC-1 Exam 102-500, objective 107. Administrative tasks medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct useradd -r appsvc
Correct. -r (--system) creates a system account: the UID is chosen from the SYS_UID_MIN to SYS_UID_MAX range in /etc/login.defs, no password ageing information is written to /etc/shadow, and no home directory is created unless -m is added.
Not correct useradd -D appsvc
Wrong. -D on its own displays useradd's defaults, and with further options it changes them in /etc/default/useradd. It does not create an account at all.
Not correct useradd -N appsvc
Wrong for this purpose. -N suppresses the creation of a group named after the user, leaving the primary group to the USERGROUPS_ENAB or GROUP default. It says nothing about the UID range.
Not correct useradd -o -u 0 appsvc
Wrong, and severe. -o permits a duplicate UID and -u 0 assigns the UID of root, creating a second fully privileged account rather than an unprivileged service account.
Why
The distinction between system and ordinary accounts is a UID range, declared in /etc/login.defs: UID_MIN and UID_MAX bound the ordinary range that useradd allocates from by default, typically starting at 1000, while SYS_UID_MIN and SYS_UID_MAX bound the range -r allocates from. Login managers and tools filter their user lists by that range. Hardening the account further is a separate step, normally `useradd -r -s /usr/sbin/nologin`.
Where this comes from
- Cited
- manual page useradd(8)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked