XK0-006 Security Practice Question
A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
jdoe ALL=(ALL) ALL
The format is 'user host=(runas) commands'. The correct entry grants jdoe full root access with password authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
jdoe ALL=(ALL) NOPASSWD: ALL
Why it's wrong here
The NOPASSWD tag suppresses the password prompt entirely, so jdoe would gain root command execution without authenticating at all — contradicting the requirement to enter their own password. It is tempting because NOPASSWD is genuinely useful for unattended automation, such as cron jobs or scripts that must run without a terminal, but that is not this scenario.
- ✗
jdoe ALL=(root) /usr/bin/su
Why it's wrong here
Granting only /usr/bin/su restricts jdoe to that binary, and su authenticates against the root password rather than jdoe's. The required entry must allow all commands via (ALL) ALL so sudo prompts for jdoe's own password.
- ✗
jdoe ALL= /bin/su -
Why it's wrong here
This permits only /bin/su, not any command, and su then demands the root password, which jdoe does not have. A full sudo entry with (ALL) ALL grants any command as root while still prompting for jdoe's own password.
- ✓
jdoe ALL=(ALL) ALL
Why this is correct
The entry jdoe ALL=(ALL) ALL grants jdoe permission to run any command as any user on all hosts, and sudo prompts for jdoe's own password by default. This satisfies both constraints: full root command access without sharing the root password.
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.