How to Fix User1 Unable to Restart Apache Using Sudoers Least Privilege?
A Linux administrator provisioned a new web server with custom administrative permissions for certain users. The administrator receives a report that user1 is unable to restart the Apache web service on this server. The administrator reviews the following output: Which of the following would most likely resolve the issue while maintaining a least privilege security model? - 
Community Votes
57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to read sudoers file output and apply the correct syntax to grant specific command permissions without over-privileging a user.
This CompTIA Linux+ XK0-005 question tests sudoers configuration for least-privilege service management. Community consensus is split between adding NOPASSWD for user1 (B) and referencing the webadmin group in sudoers (D), but the correct approach aligns with the existing custom.conf structure and NOPASSWD syntax.
Many candidates choose D, assuming the webadmin group must be explicitly listed with a % prefix, but user1 is already in the webadmin group and the issue is the missing NOPASSWD directive for the specific restart command.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The suggested answer B is correct because the sudoers output shows user1 has a custom entry but lacks theNOPASSWD: tag required to execute the systemctl restart httpd command without a password prompt. Adding NOPASSWD: after ALL= in the custom.conf line grants user1 the ability to restart the service while still restricting them to only that specific command. This maintains the least privilege model because user1 is not given blanket root access.Why the Other Options Are Wrong
Option A is incorrect because adding user1 to the wheel group grants full sudo access to all commands, violating least privilege. Option C is incorrect because uncommenting the wheel line would only help if user1 were a member of the wheel group, which they are not. Option D is a strong distractor; while listing%webadmin in sudoers could work, the question's output already shows user1 has a custom entry, and the real gap is the missing NOPASSWD: directive.Community Comment Notes
Comment [1] argues for D, noting that groups should be prefixed with%, but misses that user1's existing custom entry is the key. Comments [2] and [3] correctly identify that NOPASSWD: is the missing piece, allowing user1 to run the specific restart command without a password while keeping permissions scoped. Comment [4] highlights the confusion around group syntax but ultimately confirms user1 is already in the webadmin group. Official Reference
Exam Strategy
When analyzing sudoers output, always check for missing directives like NOPASSWD before assuming group membership is the issue. Read the existing configuration carefully to identify the exact gap rather than applying a broad fix.
systemctl, which is not currently allowed. By addingNOPASSWD:and including the restart command in the sudoers file, user1 can manage the service without requiring a password, ensuring the correct and necessary permissions are applied. The answer is not D because user1 is already a member of the webadmin group, and the permissions for restarting thehttpdservice usingsystemctlare not included in the webadmin group configuration. The correct answer is B because user1 needsNOPASSWDpermission specifically forsystemctl restart httpd, which is currently missing. Adding this to the sudoers file ensures user1 can restart the service without requiring unnecessary broader permissions.