Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A Linux administrator needs to grant the user 'jsmith' the ability to restart the httpd service without entering a password, while preventing all other sudo commands. The administrator creates the file /etc/sudoers.d/jsmith with the line: jsmith ALL=(root) NOPASSWD: /usr/bin/systemctl restart httpd. After saving the file, jsmith reports that sudo still prompts for a password. Which command should the administrator run to diagnose the issue?

⚠ Common exam trap

The trap here is assuming that syntax checking alone confirms that a sudo rule is active for a user, when in fact you must inspect the effective privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sudo -l -U jsmith

The sudo -l -U jsmith command displays the sudo privileges for jsmith, including whether NOPASSWD is applied to the specified command. This directly shows if the rule in /etc/sudoers.d/jsmith is being read and matched, which is essential for troubleshooting why a password is still required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    journalctl -u sudo

    Why it's wrong here

    journalctl -u sudo shows logs from the sudo service, which may indicate authentication failures or command denials. However, it does not display the configured sudo rules for a user, so it is less direct for diagnosing why a NOPASSWD rule is not taking effect.

  • ✓

    sudo -l -U jsmith

    Why this is correct

    The sudo -l -U jsmith command lists the sudo privileges for the specified user, showing exactly which commands jsmith may run and whether NOPASSWD applies. This directly reveals whether the sudoers.d file is being parsed correctly and whether the rule matches the intended command path, helping diagnose why a password is still requested.

  • ✗

    visudo -c

    Why it's wrong here

    visudo -c checks the syntax of the sudoers file and any included files, but it does not show the effective privileges for a specific user. While it can detect syntax errors, it would not explain why jsmith is still prompted for a password if the file is syntactically valid but not being applied as expected.

  • ✗

    grep jsmith /etc/sudoers

    Why it's wrong here

    This command searches only the main /etc/sudoers file, not the included /etc/sudoers.d/ directory. Since the rule was placed in /etc/sudoers.d/jsmith, this grep would likely return nothing and fail to diagnose the issue, as it does not inspect included files or show effective permissions.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.