200-201 Host-Based Analysis • Set 11
200-201 Host-Based Analysis Practice Test 11 — 15 questions with explanations. Free, no signup.
A security analyst is examining a Linux system for signs of a compromised user account. The analyst runs `grep ':0:0:' /etc/passwd` and finds an entry for user `backup` with UID 0. The legitimate backup user should have a UID of 1001. Which of the following is the MOST likely explanation?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.