The team lead alice should be able to add and remove members of the group `developers` herself, without being granted root and without sudo rules. Which command delegates that, and where is the delegation recorded?

LPIC-1 Exam 102-500, objective 107. Administrative tasks medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct gpasswd -A alice developers, recorded in /etc/gshadow

Correct. -A sets the list of group administrators. That list lives in the third field of the group's line in /etc/gshadow, and an administrator may then run gpasswd -a and gpasswd -d on that group.

Not correct gpasswd -a alice developers, recorded in /etc/group

Wrong for the requirement, though the command is real. Lowercase -a adds alice as an ordinary member, writing her name into the fourth field of /etc/group. Membership confers no authority over the group.

Not correct groupmod -A alice developers, recorded in /etc/group

Wrong. groupmod changes a group's own properties — its name with -n and its GID with -g — and has no -A option. It never manages membership or administrators.

Not correct usermod -aG developers alice, recorded in /etc/gshadow

Wrong. usermod -aG appends an ordinary supplementary membership, written into the fourth field of /etc/group. Being a member carries no authority to add or remove anyone else — that is what the administrator list set with gpasswd -A grants.

Why

/etc/gshadow is to /etc/group what /etc/shadow is to /etc/passwd: a root-only companion file holding the group's encrypted password, its list of administrators and a copy of its member list. gpasswd is the tool that maintains it — -A sets administrators, -M replaces the whole member list, -a and -d add and remove one member, and gpasswd with only a group name sets the group password used by newgrp.

Where this comes from

Cited
manual page gpasswd(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Administrative tasks

Practise LPIC-1 Exam 102-500