GSEC Linux Security and Hardening Practice Question
A security engineer is reviewing a production RHEL 9 server and finds that several users have entries in /etc/sudoers granting them NOPASSWD for specific commands. The engineer wants to verify which users can run commands as root without a password and also check for any syntax errors in the sudoers configuration. Which approach provides the most reliable verification?
⚠ Common exam trap
The trap here is assuming that sudo -l or group membership reveals all passwordless grants, when included files under /etc/sudoers.d can contain additional entries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use 'visudo -c' to check syntax and 'grep -r NOPASSWD /etc/sudoers /etc/sudoers.d/' to enumerate passwordless entries.
To reliably verify passwordless sudo grants, the engineer needs to enumerate all NOPASSWD entries across the main sudoers file and any drop-in files, and to validate syntax. visudo -c performs a syntax check on all included files, while a recursive grep captures every NOPASSWD occurrence. Approaches that rely on individual user sessions or logs are either incomplete or reactive, and checking group membership alone misses per-user and per-command grants.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run 'sudo -v' to validate the sudoers file and then use 'getent group sudo' to list all privileged users.
Why it's wrong here
sudo -v refreshes the invoking user's cached credentials; it does not validate the sudoers file or reveal NOPASSWD entries. Listing members of the sudo group only shows who has group-based privileges, not the specific passwordless commands granted via individual entries or included files. This approach fails to meet the verification requirement.
- ✗
Run 'sudo -l' as each user to list their allowed commands and visually inspect /etc/sudoers for NOPASSWD entries.
Why it's wrong here
Running sudo -l as each user shows that user's effective privileges, but it requires logging in as every user and does not detect syntax errors in the sudoers file. Visually inspecting /etc/sudoers is error-prone and may miss included files under /etc/sudoers.d, so this approach is incomplete and unreliable for a production audit.
- ✗
Check the file permissions on /etc/sudoers and /etc/sudoers.d, then review the sudo log in /var/log/secure for NOPASSWD usage.
Why it's wrong here
File permissions are important but do not reveal the content of passwordless grants, and /var/log/secure only shows commands that have already been run. It cannot enumerate all NOPASSWD entries or detect syntax errors before they cause problems. This method is reactive and incomplete for the stated verification goal.
- ✓
Use 'visudo -c' to check syntax and 'grep -r NOPASSWD /etc/sudoers /etc/sudoers.d/' to enumerate passwordless entries.
Why this is correct
visudo -c parses the sudoers file and any included files, reporting syntax errors without modifying anything, while a recursive grep across /etc/sudoers and /etc/sudoers.d identifies all NOPASSWD grants. Together they provide reliable syntax validation and a complete inventory of passwordless command authorizations, which is exactly what the engineer needs for verification.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.