CompTIA Linux+ (XK0-006)Services and User ManagementMedium

A system administrator is auditing the `/etc/passwd` file and notices an entry for a user `legacyuser` with `::/bin/false` as the shell. What does this configuration indicate regarding `legacyuser`'s login capabilities?

  1. AThe user can only log in via SSH with key-based authentication.
  2. BThe user can log in, but will immediately be logged out without a shell.
  3. CThe user's account is locked, preventing any login.
  4. DThe user can only execute commands with `sudo`.
Show answer & explanation

Correct answer: B. The user can log in, but will immediately be logged out without a shell.

When `/bin/false` or `/sbin/nologin` is set as a user's login shell, it means the user cannot initiate an interactive login session. Upon successful authentication, the system attempts to execute `/bin/false` (or `/sbin/nologin`), which immediately exits, thus logging the user out.

Why the other options are wrong

  • A. This shell prevents any interactive login, regardless of authentication method.
  • C. The account isn't locked; authentication is possible, but a shell isn't provided.
  • D. The ability to use `sudo` depends on `/etc/sudoers` configuration, not the login shell.

Non-Login Shells

Using `/bin/false` or `/sbin/nologin` as a user's shell prevents interactive login sessions by immediately exiting upon login.

  • User can authenticate but gets no shell.
  • Common for service accounts or disabled user accounts.
  • Different from locking an account (e.g., `passwd -l`).

Memory trick: Shell's a 'door', `false` means 'no entry'.

More Services and User Management questions