Home › Linux root and sudo security › Step 3

Lesson 3: Sudoers mastery: reading the sudoers file

Step 3 of 13 in Linux root and sudo security · video 6:39

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

A tour of the default /etc/sudoers on a RHEL-family system before any changes are made. The lesson shortens the prompt with export PS1, checks every sudoers file for syntax errors with sudo visudo -c, then strips comments and blank lines with grep -v '^#' | grep -v '^$' so that only live settings remain. Each line is then explained: Defaults such as env_reset, the env_keep lists of variables that survive into sudo, and secure_path, which fixes the directories sudo searches for commands. The rule syntax is broken down as user, host, run-as user and commands, using the root line, the %wheel group line (the percent sign marks a group) and a NOPASSWD rule for the presenter's own account, whose risk if that account is compromised is spelt out. Finally /etc/sudoers.d is listed: it needs sudo to read and is still empty, ready for modular rule files.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What does sudo visudo -c do, and when would you run it?

It parses /etc/sudoers and the files it includes and reports syntax errors without opening an editor. Running it before and after a change confirms that sudo will still accept its configuration.

2. Break down the rule %wheel ALL=(ALL) ALL field by field.

%wheel means members of the wheel group (the % marks a group), the first ALL is any host, (ALL) is run as any user, and the final ALL is any command. It gives wheel members full sudo rights, the RHEL default.

3. What is the security purpose of the secure_path Defaults setting?

It replaces the PATH used for commands run through sudo with a fixed list of trusted system directories. A malicious program placed earlier in a user's own PATH is therefore never picked up and run as root.

4. Why is a line like admin ALL=(ALL) NOPASSWD: ALL risky, even though it is common on cloud images?

It grants unlimited root access with no password check, so anyone who takes over that account, or finds its session unattended, becomes root at once. The sudo password prompt no longer acts as a second barrier.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 2: Securing the root account and configuring sudoNext: Lesson 4: Sudo privileges: limiting a user to specific commands →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.