Courseiva
Manage security →mediumMultiple Choice

EX200 Manage security Practice Question

Exhibit

User jane may run the following commands on this host:
    (ALL) NOPASSWD: /usr/bin/less

Refer to the exhibit. What is the primary security concern with this sudo configuration?

⚠ Common exam trap

The trap here is that candidates focus on the NOPASSWD or the (ALL) syntax, missing the fact that the command itself (`less`) has built-in shell escape capabilities that can be exploited for privilege escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The less command allows executing shell commands via !, enabling privilege escalation.

The `less` command, when executed with sudo, allows the user to escape to a shell by typing `!command` from within the pager. This bypasses the intended restriction of only running `/usr/bin/less` as root, enabling arbitrary command execution with elevated privileges. The NOPASSWD directive further compounds the risk by removing the password prompt, making the escalation trivial.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NOPASSWD option eliminates the need for a password.

    Why it's wrong here

    The NOPASSWD option removes the password prompt for the sudo rule, but it is not the core security flaw. If the rule required a password, jane would simply type her own password (which she knows) and then still be able to use less's ! command to spawn a root shell. The real risk is that the whitelisted command itself has an escape vector, not the absence of a password challenge.

  • ✗

    The entry uses (ALL) instead of (root), allowing jane to run as any user.

    Why it's wrong here

    Changing (ALL) to (root) would restrict which user jane can run less as, but it would not stop the escalation. When less is invoked as root, its ! command spawns a shell with root privileges regardless of whether the sudoers entry specifies (root) or (ALL). The runas user broadens the impact, but even a root-only rule allows jane to obtain a root shell because less executes commands under its own (root) privilege context.

  • ✓

    The less command allows executing shell commands via !, enabling privilege escalation.

    Why this is correct

    The less pager has a built-in feature that allows users to execute shell commands by typing ! followed by a command. When less is run with sudo as root, that shell is spawned as root, effectively giving jane a root shell. This is a well-known sudo escape vector listed in GTFOBins, and it is the primary reason this sudoers entry is dangerous, far more than the NOPASSWD or (ALL) attributes.

  • ✗

    The command /usr/bin/less can be used to read any file.

    Why it's wrong here

    The ability to read any file is a capability of the less command itself, and it is not by itself a privilege escalation. If jane were meant to audit logs or inspect system files, reading via less could be a legitimate task. The critical issue is that less does not merely read; it can execute arbitrary commands via its ! feature, which elevates her from a file reader to a root shell holder, making the command choice the primary concern.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.