CompTIA Linux+ (XK0-006)SecurityMedium

A client wants a junior administrator, jdoe, to be able to restart the httpd service using sudo without being prompted for a password, while all other sudo commands for jdoe still require password authentication. Which line, added via visudo, achieves this?

  1. Ajdoe ALL=(ALL) NOPASSWD: ALL
  2. Bjdoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart httpd
  3. C%jdoe ALL=(ALL) ALL
  4. DDefaults:jdoe !authenticate
Show answer & explanation

Correct answer: B. jdoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart httpd

A sudoers entry restricting NOPASSWD to a specific command path (/usr/bin/systemctl restart httpd) allows password-free execution of only that command, while all other sudo invocations by jdoe still require a password, satisfying the principle of least privilege.

Why the other options are wrong

  • A. NOPASSWD: ALL removes the password requirement for every sudo command, not just the httpd restart.
  • C. The %jdoe syntax targets a group named jdoe, not the user, and also grants unrestricted, password-required access to everything.
  • D. Defaults:jdoe !authenticate globally disables password prompts for jdoe on all sudo commands.

sudoers NOPASSWD Restriction

The NOPASSWD tag in /etc/sudoers (edited via visudo) can be scoped to specific commands so a user can run only that command without a password, preserving password requirements elsewhere.

  • Always edit sudoers with visudo for syntax checking
  • Format: user host=(runas) NOPASSWD: /path/to/command
  • %groupname syntax applies rules to a group
  • Scoping NOPASSWD to full paths prevents privilege escalation via PATH manipulation

Memory trick: Scope the key to one lock—NOPASSWD on one command, not the whole house.

More Security questions