CompTIA Linux+ (XK0-006)Services and User ManagementMedium
A system administrator is setting up a new service account on a Linux system that should only be able to perform specific, non-interactive tasks via cron jobs or other automated processes. The account should not have a password and should not be able to log in interactively. Which of the following `useradd` commands correctly creates such an account named `appsvc`?
- Auseradd -r -s /bin/bash appsvc
- Buseradd -u 500 -p '' appsvc
- Cuseradd -N -s /bin/false appsvc
- Duseradd -r -s /sbin/nologin -M appsvc
Show answer & explanationAnswer & explanation
Correct answer: D. useradd -r -s /sbin/nologin -M appsvc
The `-r` option creates a system user, typically without a home directory and a UID below 1000. The `-s /sbin/nologin` (or `/bin/false`) prevents interactive login. The `-M` option explicitly tells `useradd` NOT to create a home directory, which is common for service accounts.
Why the other options are wrong
- A. This creates a system user but assigns `/bin/bash`, allowing interactive login, which is contrary to the requirement.
- B. The `-u 500` forces a specific UID, but it doesn't prevent interactive login or properly configure it as a service account. An empty password (`-p ''`) is insecure and doesn't prevent login, only makes it easier.
- C. The `-N` option creates the user without a user private group, which is not the primary requirement here. While `/bin/false` prevents login, `-M` is missing for no home directory, and `-r` for a system user.
Creating Non-Interactive Service Users
To create a non-interactive service user, use `useradd` with options to make it a system user, assign a non-login shell, and prevent home directory creation.
- `-r` for system user (low UID, no expiration).
- `-s /sbin/nologin` or `/bin/false` to prevent interactive shell.
- `-M` to prevent home directory creation.
Memory trick: Service users are 'Restricted', 'Silent', 'Muted'.