CompTIA Linux+ (XK0-006)SecurityMedium
An administrator noticed that after entering a password once for a sudo command, subsequent sudo commands in the same terminal session do not prompt for a password again for several minutes. Which sudoers directive controls the length of this credential caching window?
- ADefaults timestamp_timeout=15
- BDefaults env_reset
- CDefaults !authenticate
- DDefaults passwd_tries=3
Show answer & explanationAnswer & explanation
Correct answer: A. Defaults timestamp_timeout=15
timestamp_timeout defines, in minutes, how long sudo caches successful authentication before requiring the password again; setting it to 15 caches credentials for 15 minutes. passwd_tries limits failed attempts, env_reset controls environment sanitization, and !authenticate disables password prompts entirely.
Why the other options are wrong
- B. env_reset controls whether sudo resets the environment variables, unrelated to caching time.
- C. !authenticate disables the password prompt entirely rather than setting a caching duration.
- D. passwd_tries controls how many incorrect password attempts are allowed, not caching duration.
sudo Credential Caching (timestamp_timeout)
sudo caches successful authentication for a configurable period (default 5 minutes) so repeated sudo commands don't require re-entering the password; controlled by timestamp_timeout in /etc/sudoers.
- Default timestamp_timeout is 5 minutes
- Value of 0 disables caching entirely
- sudo -k invalidates the cached timestamp immediately
- Negative value caches indefinitely until reboot
Memory trick: 'timestamp_timeout' = the sudo hourglass counting down before re-asking for your password.