EX200 Essential Tools Practice Question
A system administrator needs to replace all occurrences of 'enabled' with 'disabled' in /etc/ssh/sshd_config, but only on lines that do not start with '#'. Which sed command accomplishes this?
⚠ Common exam trap
It's easy for candidates to confuse the `!` negation operator with the `-n` suppress-print option, or mistakenly apply the substitution to commented lines instead of non-commented lines, leading to incorrect configuration changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sed '/^#/!s/enabled/disabled/g' /etc/ssh/sshd_config
It uses an address range `/^#/!` to negate lines starting with `#` (comments), then applies the substitution `s/enabled/disabled/g` only to non-comment lines. The `!` operator inverts the match, so the command acts on lines that do NOT match the pattern, which is exactly what the requirement specifies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
sed '/^#/!s/enabled/disabled/g' /etc/ssh/sshd_config
Why this is correct
The address '/^#/!' uses negated matching: sed applies the following command only to lines that do not begin with '#', i.e., active configuration directives. The s/enabled/disabled/g substitution then replaces every occurrence of 'enabled' with 'disabled' on those lines, with the g flag ensuring all matches per line, not just the first. Because sed's default action prints every input line, the output stream contains the complete updated file, and comment lines remain untouched as required.
- ✗
sed 's/enabled/disabled/g' /etc/ssh/sshd_config
Why it's wrong here
Without an address restriction, the s/// command is applied to every line of /etc/ssh/sshd_config, including lines that start with '#'. This is problematic because comments frequently contain the word 'enabled' in examples or explanatory text, so those comments get silently modified when they should remain as documentation. The g flag makes the unwanted replacement exhaustive even on comment lines, and since sed writes to standard output by default, the configuration file itself is never changed.
- ✗
sed -n '/^#/!s/enabled/disabled/gp' /etc/ssh/sshd_config
Why it's wrong here
While '/^#/!' correctly excludes comment lines, the -n flag suppresses sed's default automatic printing of every line, and the trailing p flag prints only lines that actually underwent the substitution. As a result, the command produces a partial output stream consisting solely of modified non-comment lines, omitting comments and unchanged directives entirely. That output goes to stdout rather than back into the file, so the administrator never writes changes to /etc/ssh/sshd_config and cannot rely on this as an edit operation.
- ✗
sed '/^#/s/enabled/disabled/g' /etc/ssh/sshd_config
Why it's wrong here
This command inverts the required selection by using '/^#/' as the address, which matches only lines that begin with a comment marker and applies the substitution exclusively to those lines. Consequently, active directives that should be changed are never touched because they do not start with '#', leaving every 'enabled' in the real configuration intact. Additionally, comment lines may get mangled as 'enabled' is replaced with 'disabled' in documentation, further corrupting the intended file with unwanted changes.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.