The team lead alice should be able to add and remove members of the group `developers` herself, without being granted root and without sudo rules. Which command delegates that, and where is the delegation recorded?
LPIC-1 Exam 102-500, objective 107. Administrative tasks medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct gpasswd -A alice developers, recorded in /etc/gshadow
Correct. -A sets the list of group administrators. That list lives in the third field of the group's line in /etc/gshadow, and an administrator may then run gpasswd -a and gpasswd -d on that group.
Not correct gpasswd -a alice developers, recorded in /etc/group
Wrong for the requirement, though the command is real. Lowercase -a adds alice as an ordinary member, writing her name into the fourth field of /etc/group. Membership confers no authority over the group.
Not correct groupmod -A alice developers, recorded in /etc/group
Wrong. groupmod changes a group's own properties — its name with -n and its GID with -g — and has no -A option. It never manages membership or administrators.
Not correct usermod -aG developers alice, recorded in /etc/gshadow
Wrong. usermod -aG appends an ordinary supplementary membership, written into the fourth field of /etc/group. Being a member carries no authority to add or remove anyone else — that is what the administrator list set with gpasswd -A grants.
Why
/etc/gshadow is to /etc/group what /etc/shadow is to /etc/passwd: a root-only companion file holding the group's encrypted password, its list of administrators and a copy of its member list. gpasswd is the tool that maintains it — -A sets administrators, -M replaces the whole member list, -a and -d add and remove one member, and gpasswd with only a group name sets the group password used by newgrp.
Where this comes from
- Cited
- manual page gpasswd(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked