Courseiva
Security →easyMultiple Choice

XK0-006 Security Practice Question

An administrator wants to ensure that only users in the 'wheel' group can use the sudo command. Which directive in /etc/sudoers enables this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

%wheel ALL=(ALL) ALL

%wheel ALL=(ALL) ALL grants sudo access to all members of the wheel group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    %wheel ALL=ALL

    Why it's wrong here

    The runas section is malformed: 'ALL=ALL' omits the required parentheses around the runas user, so sudoers rejects or misparses the line. The correct syntax is '%wheel ALL=(ALL) ALL'. It tempts because it correctly uses '%' for the group and 'ALL' for hosts and commands, matching the right structure apart from the runas parentheses.

  • ✗

    @wheel ALL=(ALL) ALL

    Why it's wrong here

    The '@' prefix denotes a host alias in sudoers, not a group, so this line is parsed as a host named wheel and grants nothing to the wheel group. Group specifications require the '%' prefix. It tempts because '@' is used for host lists in sudoers syntax, which is correct when restricting where a rule applies rather than who it applies to.

  • ✓

    %wheel ALL=(ALL) ALL

    Why this is correct

    The %wheel ALL=(ALL) ALL entry grants members of the wheel group permission to run any command as any user, identified by the leading % group prefix. This restricts sudo rights to wheel members alone, satisfying the requirement that only that group may use sudo.

  • ✗

    wheel ALL=(ALL) ALL

    Why it's wrong here

    This grants wheel members sudo rights but does not restrict sudo to only that group; any other authorised user or group entry still applies. The requirement is exclusivity, which needs the group specification plus removal of other grants. It tempts because it is the standard wheel sudoers line on many distributions, correct when the goal is simply enabling wheel access.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.