Courseiva

PEN-200 Linux Privilege Escalation Practice Question

Which file is essential for auditing to determine which users have been granted sudo privileges?

⚠ Common exam trap

Candidates often waste time looking into generic system logs or password files instead of targeting the definitive configuration file that dictates sudo access policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/sudoers

The /etc/sudoers file is the configuration file that controls sudo access. It defines exactly which users or groups can execute commands with elevated privileges and under what conditions. Auditing this file is the standard way to identify misconfigurations that could allow a low-privileged user to gain root access. Understanding its syntax is vital for any security professional to accurately identify and remediate potential privilege escalation paths in a Linux environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd stores user account information like home directories, shells, and UIDs. It does not contain information about sudo permissions. While it is important for identifying accounts, it provides no insight into whether those accounts have been delegated administrative rights via the sudo mechanism.

  • ✓

    /etc/sudoers

    Why this is correct

    The /etc/sudoers file is the definitive source for sudo permissions. It lists all users and groups that have been granted sudo rights and specifies the exact scope of those rights. This file is the primary target for auditing privilege assignments on any Linux system.

  • ✗

    /etc/shadow

    Why it's wrong here

    /etc/shadow contains encrypted password hashes and account expiration information. It is not used for configuring sudo permissions. While it is a critical file for system security, it does not provide any configuration details about who is authorized to run commands as root.

  • ✗

    /etc/group

    Why it's wrong here

    /etc/group defines group memberships, but it does not dictate sudo permissions. While a user might be in a group like 'sudo' or 'wheel', the actual permission to execute commands is determined by the configuration in /etc/sudoers. Therefore, this file is not sufficient for auditing sudo rights.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.