CompTIA Linux+ (XK0-006)SecurityEasy

An administrator runs 'sudo -l' as user jdoe and needs to interpret the output to determine what jdoe is authorized to do. What does this command display?

  1. AA full audit log of every sudo command previously executed on the system
  2. BThe contents of /etc/passwd for accounts with UID 0
  3. CA list of all users currently logged in with active sudo sessions
  4. DThe commands and hosts the current user is permitted to run via sudo, based on sudoers rules
Show answer & explanation

Correct answer: D. The commands and hosts the current user is permitted to run via sudo, based on sudoers rules

sudo -l lists the sudo privileges granted to the invoking user, including which commands they may run, on which hosts, and whether a password is required, based on the rules defined in /etc/sudoers or /etc/sudoers.d/.

Why the other options are wrong

  • A. Historical sudo command execution is found in logs like /var/log/secure or /var/log/auth.log, not sudo -l.
  • B. sudo -l has nothing to do with reading /etc/passwd contents.
  • C. sudo -l does not show other users' sessions; it only reports the current user's own privileges.

sudo -l

The sudo -l command lists the sudo privileges (allowed commands, hosts, and options) granted to the current user according to the sudoers configuration.

  • Shows rules from /etc/sudoers and /etc/sudoers.d/
  • Useful for verifying least-privilege configurations
  • Can be run as 'sudo -l -U username' by root to check another user's rights

Memory trick: sudo -l is your personal permission slip listing.

More Security questions