A system administrator needs to ensure that a user named 'jdoe' can execute commands as root without being prompted for a password. Which configuration change should be made?
Adding 'jdoe ALL=(ALL) NOPASSWD: ALL' to /etc/sudoers via visudo grants jdoe the ability to execute any command as any user on any host without being prompted for a password. The visudo command validates the syntax of the file before saving, preventing lockouts from malformed entries. The NOPASSWD tag overrides the default requirement to supply the user's own password when invoking sudo.
Why this answer
The sudoers directive 'jdoe ALL=(ALL) NOPASSWD: ALL' grants user jdoe the ability to run any command as any user (including root) on any host without a password prompt. This configuration must be added using visudo to ensure syntax validation and prevent lockout. The NOPASSWD tag overrides the default password requirement for sudo.
Exam trap
The trap here is that candidates often confuse the wheel group's default sudo behavior (password required) with passwordless access, or they incorrectly assume that group membership (root group) or UID changes are equivalent to sudo configuration.
How to eliminate wrong answers
Option B is wrong because '%wheel ALL=(ALL) ALL' requires members of the wheel group to enter their own password when using sudo; it does not provide passwordless access. Option C is wrong because setting the UID of jdoe to 0 would effectively make jdoe a second root user, which is a severe security risk and violates the principle of least privilege; it also does not use sudo at all. Option D is wrong because adding jdoe to the root group grants group-level permissions but does not allow command execution as root via sudo; root group membership does not bypass sudo password requirements.