Courseiva
Essential Tools →mediumMultiple Choice

EX200 Essential Tools Practice Question

A user reports that they cannot use the 'systemctl' command to manage services. The user is part of the 'wheel' group. Which configuration change is required to allow this?

⚠ Common exam trap

A common mix-up: candidates confuse group membership (like 'wheel' for sudo) with direct authorization via PolicyKit, assuming being in the 'wheel' group automatically grants all administrative privileges, when in fact systemctl relies on polkit rules for non-root users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure /etc/polkit-1/rules.d/10-admin.rules includes an admin rule for the wheel group

The 'systemctl' command requires PolicyKit authorization for non-root users to manage systemd services. The correct configuration is to add a PolicyKit rule in /etc/polkit-1/rules.d/10-admin.rules that grants the 'wheel' group administrative privileges, allowing them to invoke systemctl without a password or with appropriate authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the 'permissive' mode for systemd via systemd.conf

    Why it's wrong here

    There is no systemd.conf file or 'permissive' mode in systemd's own configuration; systemd defers authorization for systemctl operations to PolicyKit (polkit). Setting SELinux to permissive would affect MAC policy but would not grant a standard user the right to manage services, so this option does not address the user's restriction.

  • ✗

    Add the user to the 'systemd-journal' group

    Why it's wrong here

    The systemd-journal group grants access to journal logs and systemd-journald's /var/log/journal files, allowing users to read log entries without elevated privileges. Membership does not confer any permission to start, stop, or enable units, which are governed by polkit rules. So adding the user to this group would not solve the systemctl authorization failure.

  • ✗

    Add the user to /etc/sudoers with 'ALL ALL=(ALL) ALL'

    Why it's wrong here

    Editing /etc/sudoers to grant the user a blanket ALL rule would allow them to run systemctl as root via sudo, but it does not affect systemctl's own authorization mechanism, which relies on polkit for unprivileged invocation. Granting unconditional sudo access is also a security risk and is not the expected administrative fix for routine service management permissions. The correct approach is a polkit rule that permits the user to perform the action directly.

  • ✓

    Ensure /etc/polkit-1/rules.d/10-admin.rules includes an admin rule for the wheel group

    Why this is correct

    systemd's D-Bus service (org.freedesktop.systemd1) uses polkit to authorize actions such as starting, stopping, and enabling units. The default admin rule in /etc/polkit-1/rules.d/10-admin.rules (or equivalent) defines which users or groups—typically wheel—are considered administrators for these actions. Ensuring this rule actually includes the wheel group lets a member of wheel invoke systemctl directly without sudo, resolving the user's inability to use the command.

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.