20+ practice questions focused on Linux Security and Hardening — one of the most tested topics on the GIAC Security Essentials exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Linux Security and Hardening PracticeA security engineer needs to manage Mandatory Access Control (MAC) settings on a Red Hat Enterprise Linux (RHEL) system. Which TWO commands are most essential for viewing and modifying the state and file labeling of SELinux?
Explanation: Mandatory Access Control provides an additional layer of security by restricting how processes interact with files and other processes, even if they have root privileges. In SELinux-based distributions, managing the operational mode and ensuring files have the correct security context labels is vital for maintaining system stability while enforcing security policies.
Refer to the exhibit. An analyst is reviewing the /etc/shadow file to verify account security policies. Based on the entry for the user 'jdoe', what is the current password expiration policy?
Explanation: The /etc/shadow file stores sensitive account information, including hashed passwords and aging parameters. Security professionals must be able to parse this file to ensure that password rotation policies are being enforced. Each field between the colons represents a specific attribute that dictates how the system handles the user's authentication credentials.
A system administrator wants to review recent authentication failures on a modern Linux distribution that uses systemd. Which command is the most efficient way to view these logs in real-time?
Explanation: Logging is a critical component of the 'Detect' function in security. Modern Linux systems have moved away from traditional text-based logs in /var/log/ for many services, instead utilizing the journald binary format. Knowing how to query this journal is essential for responding to active security incidents and monitoring system health.
Refer to the exhibit. What is the effect of this entry in the /etc/sudoers file for a user who belongs to the 'webadmins' group?
Explanation: The sudoers file is the primary mechanism for implementing delegated administration in Linux. Poorly configured sudo rules can lead to unintended privilege escalation. Security professionals must understand how to read and write these rules to ensure that users have only the permissions they need to perform their specific job functions.
A security engineer is hardening an Ubuntu 22.04 web server that hosts a public Apache site. The site's document root is /var/www/html, owned by root:root with mode 755. Developers need to upload files without SSH access, so the engineer wants to ensure that any file or directory created inside /var/www/html by the apache user cannot be executed as a program, while still allowing PHP files to be served by the web server. Which control best accomplishes this?
Explanation: The only control that reliably prevents execution of files placed in the document root is mounting that filesystem with noexec. Because Apache delegates PHP parsing to PHP-FPM rather than executing the script as a binary, legitimate PHP still renders while uploaded binaries or shell scripts cannot run. Ownership inheritance, immutable attributes, and permissive MAC policies do not stop execution of newly created files.
+15 more Linux Security and Hardening questions available
Practice all Linux Security and Hardening questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Linux Security and Hardening. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Linux Security and Hardening questions on the GSEC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Linux Security and Hardening is tested as part of the GIAC Security Essentials blueprint. Practicing with targeted Linux Security and Hardening questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GSEC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Linux Security and Hardening is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Linux Security and Hardening practice session with instant scoring and detailed explanations.
Start Linux Security and Hardening Practice →