A daemon you are packaging must run under its own unprivileged account. The account should never be logged into, should not appear in the graphical login list, and should take a UID from the range reserved for system accounts. Which useradd option expresses that intent?

LPIC-1 Exam 102-500, objective 107. Administrative tasks medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct useradd -r appsvc

Correct. -r (--system) creates a system account: the UID is chosen from the SYS_UID_MIN to SYS_UID_MAX range in /etc/login.defs, no password ageing information is written to /etc/shadow, and no home directory is created unless -m is added.

Not correct useradd -D appsvc

Wrong. -D on its own displays useradd's defaults, and with further options it changes them in /etc/default/useradd. It does not create an account at all.

Not correct useradd -N appsvc

Wrong for this purpose. -N suppresses the creation of a group named after the user, leaving the primary group to the USERGROUPS_ENAB or GROUP default. It says nothing about the UID range.

Not correct useradd -o -u 0 appsvc

Wrong, and severe. -o permits a duplicate UID and -u 0 assigns the UID of root, creating a second fully privileged account rather than an unprivileged service account.

Why

The distinction between system and ordinary accounts is a UID range, declared in /etc/login.defs: UID_MIN and UID_MAX bound the ordinary range that useradd allocates from by default, typically starting at 1000, while SYS_UID_MIN and SYS_UID_MAX bound the range -r allocates from. Login managers and tools filter their user lists by that range. Hardening the account further is a separate step, normally `useradd -r -s /usr/sbin/nologin`.

Where this comes from

Cited
manual page useradd(8)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Administrative tasks

Practise LPIC-1 Exam 102-500