EX200 Manage users and groups Practice Question
A system administrator needs to ensure that a user named 'jdoe' can execute commands as root without being prompted for a password. Which configuration change should be made?
⚠ Common exam trap
Test-takers frequently confuse the wheel group's default sudo behavior (password required) with passwordless access, or they incorrectly assume that group membership (root group) or UID changes are equivalent to sudo configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'jdoe ALL=(ALL) NOPASSWD: ALL' to /etc/sudoers via visudo
The sudoers directive 'jdoe ALL=(ALL) NOPASSWD: ALL' grants user jdoe the ability to run any command as any user (including root) on any host without a password prompt. This configuration must be added using visudo to ensure syntax validation and prevent lockout. The NOPASSWD tag overrides the default password requirement for sudo.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add 'jdoe ALL=(ALL) NOPASSWD: ALL' to /etc/sudoers via visudo
Why this is correct
Adding 'jdoe ALL=(ALL) NOPASSWD: ALL' to /etc/sudoers via visudo grants jdoe the ability to execute any command as any user on any host without being prompted for a password. The visudo command validates the syntax of the file before saving, preventing lockouts from malformed entries. The NOPASSWD tag overrides the default requirement to supply the user's own password when invoking sudo.
- ✗
Add jdoe to the wheel group and configure /etc/sudoers with '%wheel ALL=(ALL) ALL'
Why it's wrong here
Configuring '%wheel ALL=(ALL) ALL' in /etc/sudoers allows all members of the wheel group to run any command with sudo, but this rule still demands that the invoking user authenticate with their own password. Since the question requires passwordless sudo access for jdoe, this setup does not meet that requirement unless it is paired with a NOPASSWD tag or a separate rule. The default sudo configuration for wheel on most distributions enforces password authentication.
- ✗
Set the UID of jdoe to 0
Why it's wrong here
Setting jdoe's UID to 0 makes the user numerically identical to the root superuser, granting absolute root ownership of every process and file the user creates. This bypasses sudo entirely and is extremely risky because any program run by jdoe runs with full kernel-level privileges, and it can break services that rely on distinct UIDs for user separation. It is not a standard or recommended method for granting administrative rights and would require unmounting and remounting filesystems to change the UID safely.
- ✗
Add jdoe to the root group
Why it's wrong here
Membership in the root group (GID 0) merely places jdoe in the same group as system administrators, but the group itself carries no inherent sudo or root execution permissions under the default policy. Sudo access is controlled exclusively by rules in /etc/sudoers, which must explicitly mention a user, a group name, or a %group specification. Without such a rule, being in the root group has no effect on whether jdoe can invoke sudo or run privileged commands.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.