Be able to read a permission string, run chmod/chown correctly, follow logs with tail -f, and audit setuid files and open file handles with find and lsof. The key skill is interpreting command output to decide whether access or privilege behavior is expected or suspicious.
Start practicing
Linux Fundamentals — choose a session length
Free · No account required
Domain overview
GSEC Linux Fundamentals covers file permissions, process and log inspection, and privilege-escalation artifacts on Linux hosts. Questions are scenario-based: you are given a command or a symptom and must choose the correct command, interpret its output, or explain the security implication. Expect chmod/chown, setuid/setgid, tail/less, lsof, and log-file handling to appear in practical, tool-oriented form.
Exam objectives
Applying chmod symbolic and octal modes to restrict read, write, and execute per owner, group, and other.
Using tail -f and less +F to follow log files such as /var/log/auth.log in real time.
Identifying setuid/setgid binaries with find -perm and assessing root-owned custom executables.
Interpreting lsof output for deleted-but-open files, including unlinked logs held by a process.
Confusing chmod permission bits with ownership changes; chmod cannot alter owner, only chown does.
Assuming a deleted file is gone: lsof shows unlinked files still held open by a running process.
Treating every setuid root binary as malicious; standard tools like passwd legitimately need setuid.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security administrator needs to ensure that a newly created script, 'cleanup.sh', can only be executed by the file owner, while preventing any other users from reading or writing the file. Which command achieves this configuration?
2Refer to the exhibit. A user attempts to delete a file located inside '/opt/backup', but the operation fails with a 'Permission denied' error. Given the directory permissions shown, what is the most likely cause?
3An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?
4A Linux administrator needs to identify which processes are currently consuming the most CPU resources. Which command provides an interactive, real-time view of system performance and process activity?
5A security analyst needs to determine which network ports are currently listening for incoming connections on a Linux server. Which command is best suited for this task?
6A security analyst is reviewing a compromised Linux web server. The attacker escalated to root and then ran a script that unlinked the file /var/log/auth.log to hide their tracks. The analyst runs `lsof | grep auth.log` and sees the file is still open by the rsyslogd process, but `ls /var/log/auth.log` reports that the file does not exist. Which of the following best explains why the file content is still accessible through the open file descriptor?
7A Linux server has the setuid bit set on /usr/bin/passwd. A security engineer notices that a custom binary /opt/tools/backup_tool also has the setuid bit set and is owned by root. The engineer wants to determine whether executing backup_tool will run with root privileges regardless of which user invokes it. Which of the following is the most accurate statement about how the setuid bit affects process credentials on Linux?
8A junior administrator needs to determine the default gateway configured on a Linux server to troubleshoot outbound connectivity. Which command will display the routing table and show the default route?
9A security administrator is hardening a Linux web server. The administrator needs to ensure that the Apache service, which runs as the user 'www-data', cannot be used to escalate privileges if compromised. Which file should the administrator check to verify that 'www-data' does not have a valid login shell?
10A security analyst is investigating a suspicious file on a Linux server. The analyst wants to determine the file's inode number, permissions, owner, group, size, and last modification time without modifying the file. Which command should the analyst use?
11A security analyst is investigating a compromised Linux server and wants to examine the environment variables of a running process with PID 1234 to identify potential injected malicious variables. Which command will display the environment of that specific process?
12A security analyst is examining a Linux system for signs of compromise. The analyst notices that a suspicious process is running with a parent process ID (PPID) of 1. Which command will display the process tree, showing parent-child relationships, to help identify how the process was launched?
13A security administrator is hardening a Linux server and needs to ensure that user passwords meet complexity requirements and are stored securely. Which two actions should the administrator take? (Choose two.)
Be able to read a permission string, run chmod/chown correctly, follow logs with tail -f, and audit setuid files and open file handles with find and lsof. The key skill is interpreting command output to decide whether access or privilege behavior is expected or suspicious.
The Courseiva GSEC question bank contains 13 questions in the Linux Fundamentals domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Linux Fundamentals domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included