Courseiva

SSCP Systems and Application Security Practice Question

A Linux administrator needs to configure access controls so that a specific user can run certain commands with root privileges without entering a password. Which configuration file should be modified?

⚠ Common exam trap

SSCP often tests the misconception that /etc/passwd or /etc/shadow control command privileges — candidates must remember that sudoers is the sole file governing delegated command execution, and that visudo is the safe editing tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/sudoers

The /etc/sudoers file defines which users or groups may run which commands as root (or other users), and supports the NOPASSWD tag to allow passwordless execution. Editing it with visudo ensures syntax validation and prevents concurrent-edit corruption. This is the standard mechanism for granting granular, password-free privilege escalation on Linux.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/shadow

    Why it's wrong here

    /etc/shadow stores password hashes and ageing fields, so editing it cannot grant command-level privilege escalation. It is tempting because it governs authentication, but sudoers rules for passwordless execution belong in /etc/sudoers via visudo, not the shadow file.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd holds account identity fields — UID, GID, home directory and login shell — and cannot express per-command privilege rules. It tempts because it defines users, but passwordless sudo for specific commands is configured in /etc/sudoers, not the passwd database.

  • ✓

    /etc/sudoers

    Why this is correct

    Editing /etc/sudoers lets you grant the named user targeted command privileges via a NOPASSWD entry, satisfying the passwordless requirement. The sudoers file maps users to permitted commands and their authentication rules, unlike /etc/passwd or /etc/shadow, which hold account and password data rather than privilege-escalation policy.

  • ✗

    /etc/security/limits.conf

    Why it's wrong here

    /etc/security/limits.conf sets resource ceilings such as file descriptors and CPU time per user or group, not command execution rights. It appeals because it is user-scoped and PAM-enforced, yet passwordless root command execution requires a sudoers entry, not a limits directive.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.