EX200 Manage users and groups Practice Question
Exhibit
Refer to the exhibit.
[exhibit]
[sudo -l output for user alice]
Matching Defaults entries for alice on this host:
!visiblepw, always_set_home, env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE INPUTRC KDEDIR LS_COLORS",
env_keep+="MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE",
env_keep+="LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES",
env_keep+="LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE",
env_keep+="LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY",
secure_path=/sbin\:/bin\:/usr/sbin\:/usr/bin
User alice may run the following commands on this host:
(root) /usr/bin/less /var/log/secure
(root) /usr/bin/tail /var/log/messages
[/exhibit]Alice tries to run 'sudo less /var/log/messages' and gets 'Sorry, user alice is not allowed to execute /usr/bin/less /var/log/messages as root on this host.' Why?
⚠ Common exam trap
Red Hat RHCSA often tests the misconception that sudo denies commands based on the binary path alone, when in fact argument-specific restrictions in sudoers are the cause of such errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The sudoers allows only specific commands with specific arguments
Sudoers rules can restrict commands to specific arguments. The error message indicates that the sudoers configuration explicitly allows 'less' only with certain arguments (or none), and the attempt to run 'less /var/log/messages' violates that restriction. Sudo matches both the command path and the argument list against the sudoers entries, and if the arguments do not match, access is denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The command path must exactly match, including arguments
Why it's wrong here
This is partly true, but the real issue is that the exact command line is not listed in sudoers. The path /usr/bin/less matches an allowed entry, but that entry restricts the argument to /var/log/secure; /var/log/messages is not a permitted argument, so sudo denies before any execution. Exact path matching alone is not the problem—the allowed command simply does not cover what alice requested.
- ✗
The secure_path does not include /usr/bin
Why it's wrong here
sudo's secure_path sets the PATH used to locate commands after authorization has succeeded, but it has no bearing on whether a user is allowed to run a given command. The default secure_path on RHEL includes /usr/bin, so less would be found if the sudoers policy permitted it. The denial is issued during policy evaluation, before PATH resolution ever occurs, so secure_path is irrelevant here.
- ✓
The sudoers allows only specific commands with specific arguments
Why this is correct
This is the correct reason. A sudoers entry such as 'alice ALL=(root) /usr/bin/less /var/log/secure' grants permission only for that exact command line, including the specific argument. Because alice is attempting '/usr/bin/less /var/log/messages', sudo finds no matching entry in the user's command list and reports 'not allowed to execute'—the error is purely a policy mismatch.
- ✗
The /var/log/messages file does not exist
Why it's wrong here
The error message from sudo explicitly states a permission problem, not a filesystem problem. If /var/log/messages did not exist, sudo would still allow the command (assuming the policy matched) and then less would print a 'No such file or directory' error after starting. Since the command is denied before it runs, the existence of the file is irrelevant to this failure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.