XK0-006 Security Practice Question
A Linux administrator needs to grant the user 'jsmith' the ability to restart the httpd service without entering a password, while preventing all other sudo commands. The administrator creates the file /etc/sudoers.d/jsmith with the line: jsmith ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd. After saving the file, jsmith reports that sudo still prompts for a password. Which command should the administrator run to diagnose the issue?
⚠ Common exam trap
The trap here is assuming that syntax checking alone confirms that a sudo rule is active for a user, when in fact you must inspect the effective privileges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sudo -l -U jsmith
The sudo -l -U jsmith command displays the sudo privileges for jsmith, including whether NOPASSWD is applied to the specified command. This directly shows if the rule in /etc/sudoers.d/jsmith is being read and matched, which is essential for troubleshooting why a password is still required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
journalctl -u sudo
Why it's wrong here
journalctl -u sudo shows logs from the sudo service, which may indicate authentication failures or command denials. However, it does not display the configured sudo rules for a user, so it is less direct for diagnosing why a NOPASSWD rule is not taking effect.
- ✓
sudo -l -U jsmith
Why this is correct
The sudo -l -U jsmith command lists the sudo privileges for the specified user, showing exactly which commands jsmith may run and whether NOPASSWD applies. This directly reveals whether the sudoers.d file is being parsed correctly and whether the rule matches the intended command path, helping diagnose why a password is still requested.
- ✗
visudo -c
Why it's wrong here
visudo -c checks the syntax of the sudoers file and any included files, but it does not show the effective privileges for a specific user. While it can detect syntax errors, it would not explain why jsmith is still prompted for a password if the file is syntactically valid but not being applied as expected.
- ✗
grep jsmith /etc/sudoers
Why it's wrong here
This command searches only the main /etc/sudoers file, not the included /etc/sudoers.d/ directory. Since the rule was placed in /etc/sudoers.d/jsmith, this grep would likely return nothing and fail to diagnose the issue, as it does not inspect included files or show effective permissions.
Go deeper
Related to this question
Learn chapter
Managing Storage and File Systems
Key term
systemctl
systemctl is the command-line tool used to inspect, start, stop, enable, or disable services managed by the systemd init system in Linux.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.