CompTIA Linux+ (XK0-006)SecurityMedium

An administrator noticed that after entering a password once for a sudo command, subsequent sudo commands in the same terminal session do not prompt for a password again for several minutes. Which sudoers directive controls the length of this credential caching window?

  1. ADefaults timestamp_timeout=15
  2. BDefaults env_reset
  3. CDefaults !authenticate
  4. DDefaults passwd_tries=3
Show answer & explanation

Correct answer: A. Defaults timestamp_timeout=15

timestamp_timeout defines, in minutes, how long sudo caches successful authentication before requiring the password again; setting it to 15 caches credentials for 15 minutes. passwd_tries limits failed attempts, env_reset controls environment sanitization, and !authenticate disables password prompts entirely.

Why the other options are wrong

  • B. env_reset controls whether sudo resets the environment variables, unrelated to caching time.
  • C. !authenticate disables the password prompt entirely rather than setting a caching duration.
  • D. passwd_tries controls how many incorrect password attempts are allowed, not caching duration.

sudo Credential Caching (timestamp_timeout)

sudo caches successful authentication for a configurable period (default 5 minutes) so repeated sudo commands don't require re-entering the password; controlled by timestamp_timeout in /etc/sudoers.

  • Default timestamp_timeout is 5 minutes
  • Value of 0 disables caching entirely
  • sudo -k invalidates the cached timestamp immediately
  • Negative value caches indefinitely until reboot

Memory trick: 'timestamp_timeout' = the sudo hourglass counting down before re-asking for your password.

More Security questions