Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

jdoe ALL=(ALL) ALL

The format is 'user host=(runas) commands'. The correct entry grants jdoe full root access with password authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    jdoe ALL=(ALL) NOPASSWD: ALL

    Why it's wrong here

    The NOPASSWD tag suppresses the password prompt entirely, so jdoe would gain root command execution without authenticating at all — contradicting the requirement to enter their own password. It is tempting because NOPASSWD is genuinely useful for unattended automation, such as cron jobs or scripts that must run without a terminal, but that is not this scenario.

  • ✗

    jdoe ALL=(root) /usr/bin/su

    Why it's wrong here

    Granting only /usr/bin/su restricts jdoe to that binary, and su authenticates against the root password rather than jdoe's. The required entry must allow all commands via (ALL) ALL so sudo prompts for jdoe's own password.

  • ✗

    jdoe ALL= /bin/su -

    Why it's wrong here

    This permits only /bin/su, not any command, and su then demands the root password, which jdoe does not have. A full sudo entry with (ALL) ALL grants any command as root while still prompting for jdoe's own password.

  • ✓

    jdoe ALL=(ALL) ALL

    Why this is correct

    The entry jdoe ALL=(ALL) ALL grants jdoe permission to run any command as any user on all hosts, and sudo prompts for jdoe's own password by default. This satisfies both constraints: full root command access without sharing the root password.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.