LPIC-1 Administrative Tasks Practice Question
An administrator wants to allow user 'john' to run all commands as root without a password. Which sudoers entry accomplishes this?
⚠ Common exam trap
Watch out — candidates often confuse the absence of a TAG (which defaults to requiring a password) with passwordless access, or they mistakenly think that specifying 'ALL' without the NOPASSWD tag implies no password is needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
john ALL=(ALL) NOPASSWD: ALL
The sudoers entry 'john ALL=(ALL) NOPASSWD: ALL' grants user 'john' permission to run any command as any user (including root) from any host, and the NOPASSWD tag overrides the default password requirement, allowing passwordless execution. This matches the requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
john ALL=(ALL) NOPASSWD: ALL
Why this is correct
The entry john ALL=(ALL) NOPASSWD: ALL grants john sudo rights on every host, as every user, for every command, with the NOPASSWD tag suppressing the password prompt. This precisely matches the requirement of passwordless root command execution.
- ✗
john ALL=NOPASSWD: /bin/su
Why it's wrong here
NOPASSWD applies only to /bin/su, not to all commands, so john still authenticates for everything else. It is tempting because it correctly pairs NOPASSWD with a privileged binary, and would be right if the requirement were passwordless su rather than unrestricted sudo.
- ✗
john ALL=(ALL) ALL
Why it's wrong here
Omitting a tag leaves the default, so sudo prompts john for his own password, failing the no-password requirement. It is tempting because this entry does grant full command rights as any user, which is the other half of the requirement, and matches the common default sudoers layout.
- ✗
john ALL=(ALL) PASSWD: ALL
Why it's wrong here
The PASSWD: tag forces password authentication, directly contradicting the no-password requirement; NOPASSWD is the tag that suppresses the prompt. It is tempting because PASSWD: is a real sudoers tag and appears in default entries, so it looks like valid syntax for granting command rights.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.