XK0-006 Services and User Management Practice Question
A Linux administrator is configuring sudo for a team of developers. The developers need to run commands as the user 'webadmin' without being prompted for a password, but only for commands located in /usr/local/bin. Which sudoers entry correctly implements this?
⚠ Common exam trap
The trap here is using a trailing slash to indicate a directory in sudoers, which sudo treats as a literal command name, and confusing the target user specification with the runas user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/*
The sudoers entry must specify the group, the target user (webadmin), the NOPASSWD tag, and the command path with a wildcard to allow all commands in /usr/local/bin. The correct syntax uses (webadmin) and NOPASSWD: followed by the path with /*. Other options either target the wrong user, use the wrong tag, or incorrectly specify a directory without a wildcard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
%developers ALL=(ALL) NOPASSWD: /usr/local/bin/*
Why it's wrong here
This entry allows running commands as any user (ALL) rather than specifically as webadmin. The requirement is to run as webadmin, so using (ALL) grants broader privileges than needed. It violates the principle of least privilege and does not meet the exact specification.
- ✗
%developers ALL=(webadmin) PASSWD: /usr/local/bin/*
Why it's wrong here
PASSWD is the default behavior and requires the user to enter their password. The requirement is NOPASSWD, so this entry would prompt for a password, contrary to the specified need. The tag PASSWD is redundant but explicitly enforces password prompting.
- ✓
%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/*
Why this is correct
This entry allows members of the developers group to run any command in /usr/local/bin as webadmin without a password. The wildcard * matches any command in that directory. It correctly restricts to that path and enforces NOPASSWD. This is the intended behavior.
- ✗
%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/
Why it's wrong here
This entry specifies a directory /usr/local/bin/ rather than a command. Sudo does not interpret a trailing slash as a directory; it would look for a command named exactly '/usr/local/bin/'. This is invalid and would not allow any commands. A wildcard or specific commands must be used.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
sudo
sudo is a command-line utility in Unix-like operating systems that allows a permitted user to execute a program as another user, typically the superuser (root), based on security policy settings.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.