XK0-006 Services and User Management Practice Question
A Linux administrator needs to grant temporary, time-limited administrative access to a contractor on a production server. The contractor must be able to run only `/usr/bin/systemctl restart nginx` as root without a password, and all actions must be logged. The administrator plans to use sudo. Which two steps are required to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is equating 'administrative access' with full sudo via wheel or NOPASSWD: ALL, when the scenario explicitly limits the allowed command to one systemctl invocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a file in /etc/sudoers.d/ with a rule like `contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx` and validate it with visudo -c.
Satisfying the requirement needs both a narrowly scoped sudo rule and audit logging. A drop-in file in /etc/sudoers.d with a command-specific NOPASSWD rule authorizes exactly the restart operation, while validating with visudo -c protects sudo integrity. Enabling log_output and ensuring the log destination is writable provides the session logging demanded for all actions. Together these implement least privilege and accountability without granting broad root access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a file in /etc/sudoers.d/ with a rule like `contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx` and validate it with visudo -c.
Why this is correct
A drop-in file under /etc/sudoers.d provides the specific command authorization, and NOPASSWD satisfies the no-password requirement. Restricting the command to the exact systemctl restart nginx invocation follows least privilege. Running visudo -c validates syntax and prevents a malformed sudoers file from locking out sudo, which is essential when editing production access controls.
- ✗
Add the contractor to the wheel group and rely on the default `%wheel ALL=(ALL) ALL` rule.
Why it's wrong here
Membership in wheel with the default rule grants full unrestricted sudo, which is far broader than the required single systemctl command. It also typically prompts for a password, violating the NOPASSWD requirement. This over-privileges the contractor and does not implement command restriction or the intended no-password behavior, so it is not an acceptable step for this scenario.
- ✓
Enable sudo I/O logging by adding `Defaults log_output` and ensure the sudo log file or syslog destination is writable.
Why this is correct
The requirement states all actions must be logged. sudo already logs commands, but enabling log_output captures terminal input and output for audit purposes. This, combined with a writable log destination such as /var/log/sudo-io or the configured syslog facility, provides the detailed session logging the scenario demands and complements the command-specific rule.
- ✗
Set the contractor account's shell to /sbin/nologin to limit interactive access.
Why it's wrong here
A nologin shell prevents interactive login, which would also prevent the contractor from invoking sudo interactively. While it is a useful hardening measure for service accounts, it contradicts the scenario's need for the contractor to run a command through sudo. It does not grant the required command permission or logging, so it is not one of the required steps.
- ✗
Add `contractor ALL=(ALL) NOPASSWD: ALL` to /etc/sudoers to simplify future administration.
Why it's wrong here
Granting NOPASSWD: ALL gives the contractor unrestricted root-equivalent access without a password, which violates the least-privilege requirement of running only systemctl restart nginx. It also creates a significant security exposure on a production server. Although it is syntactically valid, it does not meet the stated restriction and is therefore incorrect for this task.
Go deeper
Related to this question
Learn chapter
Installing Linux and Package Management
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
systemctl
systemctl is the command-line tool used to inspect, start, stop, enable, or disable services managed by the systemd init system in Linux.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.