How to Fix User1 Unable to Restart Apache Using Sudoers Least Privilege?

A Linux administrator provisioned a new web server with custom administrative permissions for certain users. The administrator receives a report that user1 is unable to restart the Apache web service on this server. The administrator reviews the following output: Which of the following would most likely resolve the issue while maintaining a least privilege security model? - image

  1. User1 should be added to the wheel group to manage the service.
  2. User1 should have "NOPASSWD:" after the "ALL=" in the custom.conf. Source Reference Answer
  3. The wheel line in the custom.conf file should be uncommented.
  4. Webadmin should be listed as a group in the custom.conf file.

Community Votes

B
57%
D
43%

57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to read sudoers file output and apply the correct syntax to grant specific command permissions without over-privileging a user.

This CompTIA Linux+ XK0-005 question tests sudoers configuration for least-privilege service management. Community consensus is split between adding NOPASSWD for user1 (B) and referencing the webadmin group in sudoers (D), but the correct approach aligns with the existing custom.conf structure and NOPASSWD syntax.

Many candidates choose D, assuming the webadmin group must be explicitly listed with a % prefix, but user1 is already in the webadmin group and the issue is the missing NOPASSWD directive for the specific restart command.

Community Discussion (4 comments)

NastyNutsu 👍 1
1. User1 does not have "restart" command permission 2. Only webadmin have start pemission 3. User1 is part of webadmin group so I think by listing webadmin as a group (%webadmin) should work. user1 can start and stop the web service, and will need to use sudo command to restart the service...
Pokoyo 👍 2 Selected: B
user1 need the 'NOPASSWD' in order to be able to restart the httpd service. This only enable user1 to run sudo commands on 'hppd' only and no other service.
IFBBPROSALCEDO 👍 2 Selected: B
The answer is B because user1 needs permission to restart the httpd service using systemctl, which is not currently allowed. By adding NOPASSWD: and including the restart command in the sudoers file, user1 can manage the service without requiring a password, ensuring the correct and necessary permissions are applied. The answer is not D because user1 is already a member of the webadmin group, and the permissions for restarting the httpd service using systemctl are not included in the webadmin group configuration. The correct answer is B because user1 needs NOPASSWD permission specifically for systemctl restart httpd, which is currently missing. Adding this to the sudoers file ensures user1 can restart the service without requiring unnecessary broader permissions.
makuziker 👍 3 Selected: D
I choose D. A: user1 does not need to be part of the wheel group, for that typically gives them permission to run any commands anywhere. B: Removing the password prompt before running sensitive commands would weaken security. C: User1 is not part of the wheel group. Uncommenting this line would not solve their problem. D: Correct. You specify a group entry with the % symbol, like this: %webadmin ALL=(ALL) NOPASSWD: <allowed_commands>

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The suggested answer B is correct because the sudoers output shows user1 has a custom entry but lacks the NOPASSWD: tag required to execute the systemctl restart httpd command without a password prompt. Adding NOPASSWD: after ALL= in the custom.conf line grants user1 the ability to restart the service while still restricting them to only that specific command. This maintains the least privilege model because user1 is not given blanket root access.

Why the Other Options Are Wrong

Option A is incorrect because adding user1 to the wheel group grants full sudo access to all commands, violating least privilege. Option C is incorrect because uncommenting the wheel line would only help if user1 were a member of the wheel group, which they are not. Option D is a strong distractor; while listing %webadmin in sudoers could work, the question's output already shows user1 has a custom entry, and the real gap is the missing NOPASSWD: directive.

Community Comment Notes

Comment [1] argues for D, noting that groups should be prefixed with %, but misses that user1's existing custom entry is the key. Comments [2] and [3] correctly identify that NOPASSWD: is the missing piece, allowing user1 to run the specific restart command without a password while keeping permissions scoped. Comment [4] highlights the confusion around group syntax but ultimately confirms user1 is already in the webadmin group.

Official Reference

Exam Strategy

When analyzing sudoers output, always check for missing directives like NOPASSWD before assuming group membership is the issue. Read the existing configuration carefully to identify the exact gap rather than applying a broad fix.

Related Analysis

← Back to XK0-005 Study Guide