A contractor's account must be barred from obtaining an interactive login while the account, its UID and its files stay exactly as they are. Every other user must keep working normally. Which change achieves that?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct usermod -s /sbin/nologin contractor

Correct. The seventh field of the account's /etc/passwd line becomes /sbin/nologin, a small program that prints a refusal message and exits with a non-zero status instead of giving a shell. The account, its UID and its files are untouched, and only this one user is affected.

Not correct touch /etc/nologin

Wrong scope. The presence of /etc/nologin makes pam_nologin refuse every login except root's, so it would lock out the whole user population, not just the contractor.

Not correct passwd -l contractor

Wrong. -l prefixes the hash in /etc/shadow with an exclamation mark, so no password can match. It stops password authentication only; an SSH public key already in ~/.ssh/authorized_keys still yields a shell.

Not correct chage -M 0 contractor

Wrong. Setting the maximum password age to zero expires the password so the user is forced to choose a new one, which is a prompt during login rather than a refusal of it.

Why

Two different things are called nologin and they work at different scopes. The program /sbin/nologin, described in nologin(8), is set as one account's login shell and refuses that account only. The file /etc/nologin, described in nologin(5), is read by pam_nologin and refuses every non-root login on the host. Password locking is weaker than either, because it leaves non-password authentication paths open.

Where this comes from

Cited
manual page nologin(8)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500