EX200 Manage security Practice Question
A system administrator wants to allow user 'jdoe' to execute any command as root via sudo without being prompted for a password, but only from the host 'client1.example.com'. Which sudoers rule achieves this?
⚠ Common exam trap
The trap here is that candidates often forget the NOPASSWD tag when passwordless access is required, or they use 'ALL' for the host list instead of specifying the exact hostname, assuming 'ALL' means 'all commands' rather than 'all hosts'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
jdoe client1.example.com=(root) NOPASSWD: ALL
The sudoers rule 'jdoe client1.example.com=(root) NOPASSWD: ALL' specifies the user 'jdoe', the host 'client1.example.com' as the source host from which the command is run, the target user '(root)', the NOPASSWD tag to skip password authentication, and the command 'ALL' to allow any command. This matches the requirement exactly: passwordless root access restricted to a specific client host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
jdoe client1.example.com=(root) NOPASSWD: ALL
Why this is correct
This is the correct rule. It confines the privilege to client1.example.com, specifies that commands run as root via (root), and uses the NOPASSWD tag so jdoe is not prompted for a password. The syntax exactly matches the sudoers grammar: user host_list = (runas) TAG: command_list, so it satisfies the requirement without unnecessary wildcards.
- ✗
jdoe client1.example.com=(root) ALL
Why it's wrong here
This rule is incorrectly missing the NOPASSWD tag. While the host and runas restrictions are exactly as required, without NOPASSWD sudo will invoke a password prompt, and jdoe would have to authenticate before the command runs. That conflicts with the stated requirement that the command be executed without prompting for a password.
- ✗
jdoe ALL=(root) NOPASSWD: ALL
Why it's wrong here
This rule sets the host list to ALL instead of client1.example.com. As a result, jdoe could use this sudo privilege from any managed host, which over-expands the intended scope and violates the requirement to restrict the rule to client1. Having NOPASSWD does not compensate for the incorrect host wildcard.
- ✗
jdoe ALL=(root) ALL
Why it's wrong here
This rule has two separate failures: the host list is ALL, making the privilege available from every host, and the NOPASSWD tag is absent, so a password prompt will occur. Neither component matches the requirement of a passwordless rule limited only to client1.example.com for user jdoe.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.