EX200 Manage security Practice Question
A system administrator needs to allow members of the 'developers' group to run any command as root without being prompted for a password. Which sudoers configuration line should be added?
⚠ Common exam trap
Red Hat often tests the distinction between user and group entries in sudoers, where omitting the `%` prefix causes candidates to mistakenly apply the rule to a user instead of a group, leading to a non-functional configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
%developers ALL=(ALL) NOPASSWD: ALL
The line `%developers ALL=(ALL) NOPASSWD: ALL` grants all members of the 'developers' group (indicated by the `%` prefix) permission to run any command as any user (including root) via sudo without being prompted for a password. The `NOPASSWD` tag is the key directive that bypasses password authentication, which directly matches the requirement to run commands as root without a password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
%developers ALL=(root) PASSWD: ALL
Why it's wrong here
The %developers group is correctly identified, but the PASSWD tag explicitly requires the invoking user to authenticate with their own password before the command runs. Even though the target is restricted to root and all commands are allowed, the presence of PASSWD (which is also the default behavior) defeats the passwordless requirement. Since the objective is to let developers run commands without a password, this line fails.
- ✓
%developers ALL=(ALL) NOPASSWD: ALL
Why this is correct
This line grants the developers group passwordless sudo for every command as any user on any host. The leading % marks it as a group entry, ALL=(ALL) permits running commands as any target user, and NOPASSWD: ALL overrides the default password prompt. This is the exact configuration needed to satisfy the requirement of allowing group members to run commands without supplying a password.
- ✗
developers ALL=(ALL) NOPASSWD: ALL
Why it's wrong here
The syntax lacks the mandatory % prefix before the group name, so sudo interprets 'developers' as a username rather than a group. Unless there is a system user literally named 'developers', this rule will never match the intended group members; even if such a user exists, it would only apply to that single user. To target a group in sudoers, the percent sign is required, making this entry incorrect for the stated requirement.
- ✗
%developers ALL=(ALL) ALL
Why it's wrong here
Although the %developers group and the broad ALL=(ALL) target are correct, the entry does not include the NOPASSWD tag. In sudoers, the absence of a tag means the default PASSWD behavior applies, so sudo will still prompt for the user's password before executing the command. This line therefore grants group members the ability to run commands as any user, but not without authentication, so it does not meet the passwordless access requirement.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.