From your own shell you run `su bob` and it succeeds. Compared with running `su - bob`, what is different about the shell you end up in?
LPIC-1 Exam 102-500, objective 110. Security medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct You keep your current working directory, and bob's login files are not sourced, so you are not placed in /home/bob.
Correct. Without the dash, su starts a non-login shell: the working directory does not change and bob's ~/.bash_profile is not read. Most of your exported variables survive as well, although modern util-linux su still resets a few (HOME, SHELL, USER, LOGNAME and PATH) unless you add -m/--preserve-environment.
Not correct Nothing at all; the dash is accepted only for compatibility with older shells.
Wrong. The dash is significant. It is shorthand for -l / --login and changes the shell from a non-login to a login shell.
Not correct bob's password is not requested, whereas `su - bob` always requests it.
Wrong. Both forms prompt for the target user's password, and neither does when the caller is already root. The dash has nothing to do with authentication.
Not correct The shell runs as root rather than as bob.
Wrong. su switches to the named user in both forms. It is su with no username at all that defaults to root.
Why
`su -`, `su -l` and `su --login` all start a login shell: the environment is reset to the target user's, their login scripts run, and the working directory becomes their home. Plain `su` inherits your environment, which is a classic source of confusion because root ends up with your PATH and possibly your umask. The same distinction exists for sudo: `sudo -i` is the login-shell form and `sudo -s` runs the target user's shell while keeping the current environment and directory.
Where this comes from
- Cited
- LPI exam objective 110.1
- What it says
- Switch user identity with su and sudo and understand login versus non-login shells.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked