LFCS User and Group Management Practice Question
Exhibit
Refer to the exhibit.
$ sudo cat /etc/group | grep devops
devops:x:3001:alice,bob
$ sudo cat /etc/sudoers.d/devops
%devops ALL=(ALL) /usr/bin/systemctl
$ ls -l /usr/bin/systemctl
-rwxr-xr-x 1 root root 100000 Jan 1 12:00 /usr/bin/systemctl
$ sudo -l -U alice
User alice may run the following commands on this host:
(ALL) /usr/bin/systemctl
$ sudo -l -U bob
User bob may run the following commands on this host:
(ALL) /usr/bin/systemctlA user named 'charlie' has just been added to the 'devops' group. However, when 'charlie' runs 'sudo -l', no sudo entries are shown. What is the most likely cause?
⚠ Common exam trap
Many candidates assume group changes are immediate for all processes, but Linux caches group membership at login time, so `sudo -l` reflects only the groups present when the session started.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
'charlie' must log out and log back in for the group change to take effect.
When a user is added to a new group, the group membership is only applied to new login sessions. The `sudo -l` command checks the user's current group memberships, which are cached at login time. Since 'charlie' was added to the 'devops' group while already logged in, the new group membership is not reflected until 'charlie' logs out and logs back in, or uses `newgrp` or `sg` to start a new session with the updated groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
'charlie' is not listed by name in the sudoers file.
Why it's wrong here
Sudo grants access via group membership too, so naming charlie individually is unnecessary; the devops group entry suffices. Individual listing is used when a user needs rights outside any privileged group, which is not this scenario.
- ✓
'charlie' must log out and log back in for the group change to take effect.
Why this is correct
Group membership is resolved at login and cached in the session's credential set. Charlie's existing shell still holds the old groups, so sudo matches no rule. Logging out and back in refreshes the supplementary group list, making the devops sudo entries visible.
- ✗
'charlie' is also a member of another group that restricts sudo.
Why it's wrong here
Sudo policies are additive; membership in another group cannot remove entries granted by devops. Restriction requires an explicit negation or Defaults setting, which the stem does not mention. Group-based denial is used when designing exclusion rules, not as an incidental side effect.
- ✗
The systemctl command is not executable by 'charlie'.
Why it's wrong here
Executability of systemctl governs whether a permitted command runs, not whether sudo -l lists entries. sudo -l reads policy regardless of target binary permissions. Command executability matters when a user has sudo rights but the binary itself lacks execute permission.
- ✗
The sudoers file has a syntax error.
Why it's wrong here
A syntax error would cause sudo to report a parse failure or refuse to run, not silently show no entries for one user. Syntax errors affect all users and typically produce explicit error messages. This distracts from the real cause: group membership changes require a fresh login session.
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.