easyMultiple Choice
XK0-006 Practice Question: Allow a user to run all commands as root without…
An administrator needs to allow a user to run all commands as root without a password. Which sudoers entry accomplishes this?
⚠ Common exam trap
Many candidates confuse the default behavior of `ALL` (which still requires a password) with the `NOPASSWD` tag, leading them to select option D thinking it allows passwordless execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
user ALL=(ALL) NOPASSWD: ALL
The sudoers entry `user ALL=(ALL) NOPASSWD: ALL` grants the user permission to run any command as any user (including root) without being prompted for a password. The `NOPASSWD` tag overrides the default password requirement, and the `ALL` specifications cover the host list, target user list, and command list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
user ALL=(ALL) NOPASSWD: ALL
Why this is correct
The NOPASSWD tag disables the password prompt for matching commands, and ALL in the command field permits every binary. Combined with ALL=(ALL) runas and host specifications, this grants the user unrestricted root execution without authentication, exactly as the policy demands.
- ✗
user ALL=(ALL) !ALL
Why it's wrong here
The !ALL negation removes every command from the permitted set, so the user can run nothing at all. Negation lists are used to carve exceptions out of a broader grant, for example denying shutdown or passwd while allowing the rest.
- ✗
user ALL=(ALL) PASSWD: ALL
Why it's wrong here
The PASSWD: tag explicitly forces a password prompt, the opposite of the requirement, so the user must authenticate before each command. This tag is used deliberately when policy demands re-authentication for privileged actions rather than cached or absent credentials.
- ✗
user ALL=(ALL) ALL
Why it's wrong here
This entry grants the user sudo rights to all commands but still prompts for their own password, because no NOPASSWD tag is present. It is the standard full-sudo grant used when password confirmation at each invocation is acceptable and desired for accountability.
Go deeper
Related to this question
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.