CompTIA Linux+ (XK0-006)SecurityMedium
A client wants a junior administrator, jdoe, to be able to restart the httpd service using sudo without being prompted for a password, while all other sudo commands for jdoe still require password authentication. Which line, added via visudo, achieves this?
- Ajdoe ALL=(ALL) NOPASSWD: ALL
- Bjdoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart httpd
- C%jdoe ALL=(ALL) ALL
- DDefaults:jdoe !authenticate
Show answer & explanationAnswer & explanation
Correct answer: B. jdoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart httpd
A sudoers entry restricting NOPASSWD to a specific command path (/usr/bin/systemctl restart httpd) allows password-free execution of only that command, while all other sudo invocations by jdoe still require a password, satisfying the principle of least privilege.
Why the other options are wrong
- A. NOPASSWD: ALL removes the password requirement for every sudo command, not just the httpd restart.
- C. The %jdoe syntax targets a group named jdoe, not the user, and also grants unrestricted, password-required access to everything.
- D. Defaults:jdoe !authenticate globally disables password prompts for jdoe on all sudo commands.
sudoers NOPASSWD Restriction
The NOPASSWD tag in /etc/sudoers (edited via visudo) can be scoped to specific commands so a user can run only that command without a password, preserving password requirements elsewhere.
- Always edit sudoers with visudo for syntax checking
- Format: user host=(runas) NOPASSWD: /path/to/command
- %groupname syntax applies rules to a group
- Scoping NOPASSWD to full paths prevents privilege escalation via PATH manipulation
Memory trick: Scope the key to one lock—NOPASSWD on one command, not the whole house.