CompTIA Linux+ (XK0-006)SecurityEasy
An administrator runs 'sudo -l' as user jdoe and needs to interpret the output to determine what jdoe is authorized to do. What does this command display?
- AA full audit log of every sudo command previously executed on the system
- BThe contents of /etc/passwd for accounts with UID 0
- CA list of all users currently logged in with active sudo sessions
- DThe commands and hosts the current user is permitted to run via sudo, based on sudoers rules
Show answer & explanationAnswer & explanation
Correct answer: D. The commands and hosts the current user is permitted to run via sudo, based on sudoers rules
sudo -l lists the sudo privileges granted to the invoking user, including which commands they may run, on which hosts, and whether a password is required, based on the rules defined in /etc/sudoers or /etc/sudoers.d/.
Why the other options are wrong
- A. Historical sudo command execution is found in logs like /var/log/secure or /var/log/auth.log, not sudo -l.
- B. sudo -l has nothing to do with reading /etc/passwd contents.
- C. sudo -l does not show other users' sessions; it only reports the current user's own privileges.
sudo -l
The sudo -l command lists the sudo privileges (allowed commands, hosts, and options) granted to the current user according to the sudoers configuration.
- Shows rules from /etc/sudoers and /etc/sudoers.d/
- Useful for verifying least-privilege configurations
- Can be run as 'sudo -l -U username' by root to check another user's rights
Memory trick: sudo -l is your personal permission slip listing.