CompTIA Linux+ (XK0-006)Services and User ManagementHard

A security auditor is reviewing the `/etc/shadow` file on a critical server to ensure password security policies are being enforced. They encounter the following entry for a user `auditor`: `auditor:$6$salt$hashedpassword:19782:0:90:7:::`. What does the third field (`90`) indicate for the `auditor` user?

  1. AThe number of days since the last password change.
  2. BThe minimum number of days between password changes.
  3. CThe number of days of warning before password expiration.
  4. DThe maximum number of days the password is valid.
Show answer & explanation

Correct answer: D. The maximum number of days the password is valid.

The `/etc/shadow` file contains various password aging parameters. The third field (indexed 2, after username and password hash) is the 'number of days since epoch (January 1, 1970) that the password was last changed'. The fourth field (indexed 3) is 'Minimum number of days between password changes'. The fifth field (indexed 4) is 'Maximum number of days the password is valid'. Thus, `90` in the fifth position indicates the maximum number of days the password is valid.

Why the other options are wrong

  • A. The second field (19782) indicates the number of days since last password change (epoch).
  • B. The fourth field (0) indicates the minimum number of days between password changes.
  • C. The sixth field (7) indicates the number of days of warning before password expires.

/etc/shadow Fields

The `/etc/shadow` file stores secure user account information, including password hashes and password aging policies, with each field separated by a colon.

  • Contains 9 fields, though not all are always used.
  • Fields 3-7 define password aging policies.
  • Only accessible by root.

Memory trick: SHADOW's secrets: User, Hash, Last, Min, MAX, Warn, Inactive, Expire, Reserved.

More Services and User Management questions