TechNuggets Academy

Linux Security

Free GIAC Security Essentials practice — 6 questions on Linux Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Linux Security
A Linux security analyst must locate every SUID root binary on a production ext4 filesystem to check for GTFOBins-exploitable programs, while suppressing permission-denied noise from restricted directories. Which command BEST accomplishes this?
-perm -4000 matches files where the setuid bit is set regardless of other bits, -type f restricts to regular files, and redirecting stderr to /dev/null suppresses 'Permission denied' clutter from directories the scanning user can't traverse.
Question 2 of 6 · Linux Security
You need an auditd rule that logs every write and attribute change to /etc/shadow, tagged with a searchable key for later ausearch queries. Which rule is correct?
-w sets a watch on the file; -p wa specifies write and attribute-change permissions, which are the only meaningful audit permissions for a regular file (read and execute don't apply the same way and would generate excessive noise); -k assigns a filter key for ausearch -k shadow_watch.
Question 3 of 6 · Linux Security
An administrator wants to lock a local Linux account for 15 minutes after 5 consecutive failed password authentication attempts using PAM's faillock module. Which configuration in /etc/security/faillock.conf achieves this?
faillock.conf uses 'deny' to set the number of failed attempts before lockout and 'unlock_time' in seconds for how long the account stays locked; deny=5 unlock_time=900 correctly locks after 5 failures for 15 minutes (900 seconds).
Question 4 of 6 · Linux Security
In /etc/shadow, the entry 'jdoe:$6$abc123...:19500:1:90:7:14:19600:' includes several colon-separated fields. What does the value '1' in the third position (minimum password age field) represent?
The shadow file format is user:hash:lastchange:min:max:warn:inactive:expire:reserved. The 'min' field specifies the minimum number of days that must pass after a password change before the user is permitted to change it again, preventing rapid password cycling to defeat history checks.
Question 5 of 6 · Linux Security
A junior admin adds this sudoers entry to let a helpdesk user edit configuration files without a password: 'jdoe ALL=(root) NOPASSWD: /usr/bin/vi /etc/app/app.conf'. Why is this a serious security risk on the exam's threat model?
vi (and many other interactive editors/pagers) support shell escapes such as ':!/bin/bash', which spawn a subshell inheriting the sudo-elevated privileges — a classic GTFOBins privilege escalation. Restricting sudo to a specific binary and argument does not prevent that binary's built-in shell-escape functionality from granting full root access.
Question 6 of 6 · Linux Security
A file on an ext4 filesystem must be protected so that no user, including root, can modify, delete, or rename it until the protection is explicitly removed. Which command applies this protection?
chattr +i sets the immutable attribute on ext2/3/4 filesystems, preventing any modification, deletion, renaming, or linking of the file — even by root — until the attribute is removed with chattr -i. This is verified with lsattr.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →