Be able to harden a Linux host end to end: lock down boot and physical access, add auditd watches, build least-privilege nftables rules, and configure PAM pwquality. The single most important thing is knowing which file or command actually enforces each control.
Start practicing
Linux Security and Hardening — choose a session length
Free · No account required
Domain overview
This domain covers hardening Linux hosts on the GSEC exam: controlling physical and boot access, configuring auditd file watches, writing nftables rules that default-deny, and enforcing password quality with PAM. Questions are scenario-based, asking you to pick the correct commands, config files, or control combinations rather than recall definitions.
Exam objectives
Boot-loader and BIOS/UEFI passwords plus GRUB restrictions to stop unauthorized physical or single-user boot access
auditd watch rules on /etc/passwd and /etc/group, and how audit records are written and queried with ausearch
nftables default-drop input chains that permit only established traffic and SSH on port 22
PAM pwquality settings in /etc/security/pwquality.conf enforcing length, character class, and complexity requirements
Assuming file permissions alone stop boot tampering; physical access controls like BIOS/UEFI and GRUB passwords are also required.
Writing nftables rules that accept SSH but forget the default drop policy, leaving all other inbound ports open.
Setting password length in login.defs or PAM but not enabling the pwquality module, so the policy is never enforced.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A system administrator needs to harden a public-facing Linux server against automated brute-force attacks. Which configuration change in the /etc/ssh/sshd_config file provides the most significant reduction in the attack surface regarding credential stuffing?
2An information security auditor discovers a custom compiled binary in a shared directory with the following permissions: -rwsr-xr-x. The file is owned by the root user. What is the primary security implication of this finding?
3To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?
4A security administrator needs to block all incoming traffic to a server except for SSH (port 22) using the nftables framework. Which configuration approach best follows the principle of least privilege?
5A security engineer is configuring a Linux server to enforce password quality for all local accounts. The requirement is that passwords must be at least 14 characters long, contain at least one uppercase letter, one lowercase letter, one digit, and one special character, and must not repeat any of the last 5 passwords. Which file should the engineer edit to enforce these settings?
6A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?
7A junior administrator is preparing a new Ubuntu server for production. The security policy states that the root account must not be usable for direct interactive logon, and that administrative tasks must be performed through a named account with elevated privileges. Which configuration change best enforces this policy?
8A security engineer is reviewing a production RHEL 9 server and finds that several users have entries in /etc/sudoers granting them NOPASSWD for specific commands. The engineer wants to verify which users can run commands as root without a password and also check for any syntax errors in the sudoers configuration. Which approach provides the most reliable verification?
9A security analyst is hardening a fleet of Linux servers and wants to reduce the risk of privilege escalation through file capabilities and setuid binaries. The analyst plans to audit and restrict these mechanisms. Which two actions best support this goal? (Choose two.)
10A security administrator is configuring auditd on a Linux server to meet a compliance requirement that all changes to user and group files be logged. The administrator adds a watch on /etc/passwd and /etc/group. After applying the rules, the administrator notices that modifications made using the 'vipw' and 'vigr' commands are not generating audit events, even though direct edits with a text editor are logged. Which explanation best describes why this occurs?
11A system administrator is hardening a Linux server and wants to ensure that users cannot log in with empty passwords. Which command should the administrator use to check for accounts with empty password fields in /etc/shadow?
12A security engineer is implementing file integrity monitoring on a Linux server. The engineer wants to use AIDE to detect unauthorized changes to critical system files. After initializing the AIDE database, which command should be used to perform a manual check and compare the current file system state against the baseline?
13A security administrator is hardening the boot process of a production Ubuntu 22.04 server that uses GRUB 2. The policy requires that any interactive modification to the kernel command line at the GRUB menu must be blocked, and that the bootloader configuration file must be unreadable by unprivileged users. Which action should the administrator take to meet these requirements?
Be able to harden a Linux host end to end: lock down boot and physical access, add auditd watches, build least-privilege nftables rules, and configure PAM pwquality. The single most important thing is knowing which file or command actually enforces each control.
The Courseiva GSEC question bank contains 13 questions in the Linux Security and Hardening domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Linux Security and Hardening domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included