Why is visudo the recommended way to edit /etc/sudoers rather than opening the file directly in an editor?

LPIC-1 Exam 102-500, objective 110. Security easy

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct It is the only editor able to open a file owned by root with mode 0440.

Wrong. Any editor running as root can open and write that file; root is not stopped by the read-only mode bits.

Not correct It compiles /etc/sudoers into the binary format that sudo actually reads at runtime.

Wrong. There is no compiled form. sudoers stays a plain text file and sudo parses it on every invocation.

Correct It locks the file against simultaneous edits and refuses to install a version that fails its syntax check.

Correct. visudo takes a lock so two administrators cannot clobber each other, and it parses the result before saving. A syntax error in sudoers can lock everyone out of sudo, so this check is the whole point.

Not correct It signs the file with root's GPG key so that sudo can detect tampering.

Wrong. sudo performs no signature verification. It relies on the file being owned by root and not writable by anyone else, and refuses to run if the ownership or mode is wrong.

Why

visudo picks its editor from the SUDO_EDITOR, VISUAL or EDITOR variables, subject to the editor and env_editor settings in sudoers itself. `visudo -c` checks the syntax without editing, and `visudo -f /etc/sudoers.d/webteam` edits a drop-in file with the same locking and checking. Files under /etc/sudoers.d must also be root-owned and mode 0440.

Where this comes from

Cited
LPI exam objective 110.1
What it says
Configure sudo and edit /etc/sudoers safely.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500