EX200 Manage security Practice Question
You are the system administrator for a small company. A developer, Alice, needs to restart the web server (httpd.service) on server 'web1.example.com' without being prompted for a password. She should also be able to run any command as root on that server, but only from the server itself (not remotely). Currently, Alice can SSH into the server using her SSH key, but when she runs 'sudo systemctl restart httpd', she is prompted for her password. You have verified that Alice is in the 'wheel' group. The sudoers file currently has the line '%wheel ALL=(ALL) ALL'. You want to modify sudoers to satisfy the requirement with minimal privilege. Which action should you take?
⚠ Common exam trap
The trap here is that candidates often forget the `NOPASSWD:` tag when the requirement explicitly says 'without being prompted for a password', leading them to choose Option C, which grants the command but still requires authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'alice web1.example.com=(root) NOPASSWD: /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
It grants Alice passwordless sudo access specifically to the command `/usr/bin/systemctl restart httpd` on the host `web1.example.com` as root, meeting the requirement with minimal privilege. The `NOPASSWD:` tag is essential to bypass the password prompt, and the host restriction ensures the rule applies only when Alice is on that server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add 'alice web1.example.com=(root) NOPASSWD: ALL' to /etc/sudoers.d/alice.
Why it's wrong here
The rule grants alice passwordless sudo rights to execute any command as root on the host web1.example.com. While NOPASSWD removes the password prompt, the command specification ALL is far broader than the single restart needed. This violates least privilege: alice could run useradd, visudo, or other administrative commands.
- ✓
Add 'alice web1.example.com=(root) NOPASSWD: /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
Why this is correct
This entry precisely scopes alice's sudo privilege to the exact systemctl invocation required to restart httpd, with NOPASSWD so the service can be restarted without interactive password entry. The command path /usr/bin/systemctl is verified as a literal command; arguments are permitted as given. This meets the stated requirement of minimal access while allowing the action.
- ✗
Add 'alice web1.example.com=(root) /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
Why it's wrong here
This rule limits alice to the appropriate systemctl restart httpd command, but without the NOPASSWD tag she will be prompted for her password. If the goal is passwordless restart—as implied by the requirement—the absence of NOPASSWD makes the rule functionally insufficient. Also note that sudo will still require a valid password and tty, potentially blocking automation.
- ✗
Change '%wheel ALL=(ALL) ALL' to '%wheel ALL=(ALL) NOPASSWD: ALL' in /etc/sudoers.
Why it's wrong here
Modifying the wheel group line affects every user in the wheel group, not just alice, and grants them all passwordless root access. This is a system-wide change that drastically increases the attack surface and violates the principle of least privilege. The original line already grants full root; adding NOPASSWD only removes the password check without addressing command scoping.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on EX200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A system administrator wants to allow user 'jdoe' to execute any command as root via sudo without being prompted for a password, but only from the host 'client1.example.com'. Which sudoers rule achieves this?
hard- ✓ A.jdoe client1.example.com=(root) NOPASSWD: ALL
- B.jdoe client1.example.com=(root) ALL
- C.jdoe ALL=(root) NOPASSWD: ALL
- D.jdoe ALL=(root) ALL
Why A: The sudoers rule 'jdoe client1.example.com=(root) NOPASSWD: ALL' specifies the user 'jdoe', the host 'client1.example.com' as the source host from which the command is run, the target user '(root)', the NOPASSWD tag to skip password authentication, and the command 'ALL' to allow any command. This matches the requirement exactly: passwordless root access restricted to a specific client host.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.