sudo

A Unix-like system utility that lets a permitted user run specific commands with another account's privileges, usually root, under a written policy that logs each use.

sudo lets a user on a Unix-like system run a command with the privileges of another account, usually the superuser, root. The user commonly authenticates with their own password rather than the target account’s, sudo checks a policy stating who may run which commands as whom, and each use is logged. The ISC2 exam outline names it in 5.5: “Privilege escalation (e.g., use of sudo, auditing its use)”. This is managed, authorised escalation, distinct from the attack also called privilege escalation.

Its control value has two parts, the policy and the audit trail. A narrow rule letting a named person run a named command supports least privilege and ties each privileged action to an individual. A rule that lets a user run anything loses the policy half and keeps only the log, and a shared root password loses both. NIST SP 800-53 Rev. 5 asks for the use of privileged functions to be logged (AC-6(9)) and for non-privileged users to be prevented from executing them (AC-6(10)). The logs help only if someone reviews them.

Exam relevance: a scenario is likely to contrast administrators sharing the root password with administrators using individual accounts and sudo. Candidates are expected to see accountability as the gain, and to recognise that sudo helps only when its policy is narrow and its logs are reviewed.