Courseiva
Manage security →easyMultiple Choice

EX200 Manage security Practice Question

To allow a user to run a specific program with root privileges without providing the root password, which configuration file should be modified?

⚠ Common exam trap

Candidates often mistakenly think that modifying /etc/passwd or /etc/security/limits.conf can grant root privileges, but only /etc/sudoers controls passwordless sudo access for specific programs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/sudoers

The /etc/sudoers file is the correct configuration file to modify because it controls the sudo command, which allows specified users to execute programs with root privileges. By adding an entry such as `username ALL=(ALL) NOPASSWD: /path/to/program`, the user can run that specific program without being prompted for a password. This is the standard mechanism in Red Hat Enterprise Linux for granting passwordless privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/passwd

    Why it's wrong here

    The /etc/passwd file stores essential user account information such as usernames, UID/GID values, home directories, and login shells. It is world-readable and does not contain any authorization rules or permissions for executing commands with elevated privileges. While sudo rules reference usernames found in /etc/passwd, this file itself cannot grant or restrict root-level command execution.

  • ✗

    /etc/security/limits.conf

    Why it's wrong here

    The /etc/security/limits.conf file is used by the pam_limits module to enforce per-user or per-group resource limits, such as maximum open files, CPU time, memory, or number of processes. It controls how many system resources a user may consume but has no mechanism for defining command-level authorization. Therefore, it cannot allow a user to run a specific program with root privileges; that is the domain of sudo configuration.

  • ✓

    /etc/sudoers

    Why this is correct

    The /etc/sudoers file is the central configuration for the sudo utility, which permits designated users to execute commands as root or another user. Rules use a syntax like "user host=(runas) commands" and can be tailored to allow a specific binary without granting a general root shell. This file must always be edited with the visudo command to prevent syntax errors that could break sudo, and it supports including drop-in files from /etc/sudoers.d.

  • ✗

    /etc/sysconfig/sshd

    Why it's wrong here

    The /etc/sysconfig/sshd file is a configuration file that sets command-line options or environment variables for the OpenSSH daemon (sshd) on RHEL-family systems. It controls SSH server behaviors such as protocol settings or service startup arguments, but it does not affect local authorization for running commands. Granting root privileges is completely separate from SSH daemon configuration, so this file is irrelevant to the stated goal.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.