Courseiva

XK0-006 Services and User Management Practice Question

A Linux administrator is configuring sudo for a team of developers. The developers need to run commands as the user 'webadmin' without being prompted for a password, but only for commands located in /usr/local/bin. Which sudoers entry correctly implements this?

⚠ Common exam trap

The trap here is using a trailing slash to indicate a directory in sudoers, which sudo treats as a literal command name, and confusing the target user specification with the runas user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/*

The sudoers entry must specify the group, the target user (webadmin), the NOPASSWD tag, and the command path with a wildcard to allow all commands in /usr/local/bin. The correct syntax uses (webadmin) and NOPASSWD: followed by the path with /*. Other options either target the wrong user, use the wrong tag, or incorrectly specify a directory without a wildcard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    %developers ALL=(ALL) NOPASSWD: /usr/local/bin/*

    Why it's wrong here

    This entry allows running commands as any user (ALL) rather than specifically as webadmin. The requirement is to run as webadmin, so using (ALL) grants broader privileges than needed. It violates the principle of least privilege and does not meet the exact specification.

  • ✗

    %developers ALL=(webadmin) PASSWD: /usr/local/bin/*

    Why it's wrong here

    PASSWD is the default behavior and requires the user to enter their password. The requirement is NOPASSWD, so this entry would prompt for a password, contrary to the specified need. The tag PASSWD is redundant but explicitly enforces password prompting.

  • ✓

    %developers ALL=(webadmin) NOPASSWD: /usr/local/bin/*

    Why this is correct

    This entry allows members of the developers group to run any command in /usr/local/bin as webadmin without a password. The wildcard * matches any command in that directory. It correctly restricts to that path and enforces NOPASSWD. This is the intended behavior.

  • ✗

    %developers ALL=(webadmin) NOPASSWD: /usr/local/bin/

    Why it's wrong here

    This entry specifies a directory /usr/local/bin/ rather than a command. Sudo does not interpret a trailing slash as a directory; it would look for a command named exactly '/usr/local/bin/'. This is invalid and would not allow any commands. A wildcard or specific commands must be used.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.