Courseiva
Manage security →easyMultiple Choice

EX200 Manage security Practice Question

A system administrator needs to allow members of the 'developers' group to run any command as root without being prompted for a password. Which sudoers configuration line should be added?

⚠ Common exam trap

Red Hat often tests the distinction between user and group entries in sudoers, where omitting the `%` prefix causes candidates to mistakenly apply the rule to a user instead of a group, leading to a non-functional configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

%developers ALL=(ALL) NOPASSWD: ALL

The line `%developers ALL=(ALL) NOPASSWD: ALL` grants all members of the 'developers' group (indicated by the `%` prefix) permission to run any command as any user (including root) via sudo without being prompted for a password. The `NOPASSWD` tag is the key directive that bypasses password authentication, which directly matches the requirement to run commands as root without a password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    %developers ALL=(root) PASSWD: ALL

    Why it's wrong here

    The %developers group is correctly identified, but the PASSWD tag explicitly requires the invoking user to authenticate with their own password before the command runs. Even though the target is restricted to root and all commands are allowed, the presence of PASSWD (which is also the default behavior) defeats the passwordless requirement. Since the objective is to let developers run commands without a password, this line fails.

  • ✓

    %developers ALL=(ALL) NOPASSWD: ALL

    Why this is correct

    This line grants the developers group passwordless sudo for every command as any user on any host. The leading % marks it as a group entry, ALL=(ALL) permits running commands as any target user, and NOPASSWD: ALL overrides the default password prompt. This is the exact configuration needed to satisfy the requirement of allowing group members to run commands without supplying a password.

  • ✗

    developers ALL=(ALL) NOPASSWD: ALL

    Why it's wrong here

    The syntax lacks the mandatory % prefix before the group name, so sudo interprets 'developers' as a username rather than a group. Unless there is a system user literally named 'developers', this rule will never match the intended group members; even if such a user exists, it would only apply to that single user. To target a group in sudoers, the percent sign is required, making this entry incorrect for the stated requirement.

  • ✗

    %developers ALL=(ALL) ALL

    Why it's wrong here

    Although the %developers group and the broad ALL=(ALL) target are correct, the entry does not include the NOPASSWD tag. In sudoers, the absence of a tag means the default PASSWD behavior applies, so sudo will still prompt for the user's password before executing the command. This line therefore grants group members the ability to run commands as any user, but not without authentication, so it does not meet the passwordless access requirement.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.