Courseiva
easyMultiple Choice

XK0-006 Practice Question: Allow a user to run all commands as root without…

An administrator needs to allow a user to run all commands as root without a password. Which sudoers entry accomplishes this?

⚠ Common exam trap

Many candidates confuse the default behavior of `ALL` (which still requires a password) with the `NOPASSWD` tag, leading them to select option D thinking it allows passwordless execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

user ALL=(ALL) NOPASSWD: ALL

The sudoers entry `user ALL=(ALL) NOPASSWD: ALL` grants the user permission to run any command as any user (including root) without being prompted for a password. The `NOPASSWD` tag overrides the default password requirement, and the `ALL` specifications cover the host list, target user list, and command list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    user ALL=(ALL) NOPASSWD: ALL

    Why this is correct

    The NOPASSWD tag disables the password prompt for matching commands, and ALL in the command field permits every binary. Combined with ALL=(ALL) runas and host specifications, this grants the user unrestricted root execution without authentication, exactly as the policy demands.

  • ✗

    user ALL=(ALL) !ALL

    Why it's wrong here

    The !ALL negation removes every command from the permitted set, so the user can run nothing at all. Negation lists are used to carve exceptions out of a broader grant, for example denying shutdown or passwd while allowing the rest.

  • ✗

    user ALL=(ALL) PASSWD: ALL

    Why it's wrong here

    The PASSWD: tag explicitly forces a password prompt, the opposite of the requirement, so the user must authenticate before each command. This tag is used deliberately when policy demands re-authentication for privileged actions rather than cached or absent credentials.

  • ✗

    user ALL=(ALL) ALL

    Why it's wrong here

    This entry grants the user sudo rights to all commands but still prompts for their own password, because no NOPASSWD tag is present. It is the standard full-sudo grant used when password confirmation at each invocation is acceptable and desired for accountability.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.