Prepare for the LPIC3 303 Security Test. Engage with flashcards and multiple-choice questions, complete with hints and detailed explanations. Ace your exam!

Multiple Choice

What line in the /etc/pam.d/su file allows root to use su without supplying passwords?

The line in the /etc/pam.d/su file that allows the root user to use the `su` command without needing to supply a password is indeed associated with the `pam_rootok.so` module specified as sufficient. Using the `pam_rootok.so` module enables a mechanism where if the user is the root, they are automatically granted access without prompting for a password. This is particularly useful for convenience when operating as the root user on a system, as it streamlines the process by eliminating the need for additional authentication in scenarios where the root account is already logged in and accessing administrative functions. The "sufficient" control flag means that if this module succeeds, the subsequent authentication modules will not be invoked, making it a practical approach to manage root access efficiently. In contrast, if it were marked as "required," the presence of additional conditions would still necessitate further authentication steps, which is not the intended behavior for enabling password-less access for the root account.

The line in the /etc/pam.d/su file that allows the root user to use the su command without needing to supply a password is indeed associated with the pam_rootok.so module specified as sufficient.

Using the pam_rootok.so module enables a mechanism where if the user is the root, they are automatically granted access without prompting for a password. This is particularly useful for convenience when operating as the root user on a system, as it streamlines the process by eliminating the need for additional authentication in scenarios where the root account is already logged in and accessing administrative functions.

The "sufficient" control flag means that if this module succeeds, the subsequent authentication modules will not be invoked, making it a practical approach to manage root access efficiently. In contrast, if it were marked as "required," the presence of additional conditions would still necessitate further authentication steps, which is not the intended behavior for enabling password-less access for the root account.