Select the TWO true statements about /etc/at.allow and /etc/at.deny.
LPIC-1 Exam 102-500, objective 107. Administrative tasks hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Choose 2.
Correct If /etc/at.allow exists, only the users named in it may submit jobs, and /etc/at.deny is not consulted at all.
True. at.allow takes precedence; where it exists it is the whole policy, and at.deny is ignored.
Correct If neither file exists, only the superuser may use at.
True. That is the documented fallback, which is why distributions that want at open to everyone ship an empty /etc/at.deny rather than no file at all.
Not correct The files list accounts by numeric UID, one per line.
False. Both files contain user names, one per line. Numeric UIDs are not matched.
Not correct The files govern at only; atq and atrm are unrestricted by them.
False. The permission check applies to the at family as a whole, so a user denied access cannot list or remove jobs through these tools either.
Not correct A line in /etc/at.allow may name a group, which grants access to all its members.
False. There is no group syntax; each member has to be listed individually.
Why
at and cron use the same two-file pattern, allow beats deny, but their empty-set defaults differ in spirit: at documents superuser-only when both files are absent, whereas cron implementations commonly ship a cron.deny so that ordinary users can schedule work. Check for the presence of the files first, then their contents; reading only at.deny will mislead you whenever at.allow exists.
Where this comes from
- Cited
- manual page at(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 107 and space the ones you get wrong.
More questions on this objective
- The account alice already belongs to the supplementary groups audio and video. You must additionally put her in the group developers while keeping her existing memberships. Which command does that? machine-checked
- A departing employee's account bob must be deleted together with his home directory and mail spool. Which command does all of that in one step? machine-checked
- You want every newly created account to start with a company-standard .bashrc already in its home directory. Where do you place that file? machine-checked
- On a host whose accounts come partly from local files and partly from a directory service, `grep alice /etc/passwd` returns nothing even though `id alice` works. Which command shows alice's account entry the way the system itself resolves it? machine-checked
- Policy says passwords must be changed at least every 90 days, and the account carol must comply. Which command sets that maximum password age? machine-checked
- A line in /etc/group reads `developers:x:1500:alice,bob`. What does the final field contain? machine-checked