CHFI OS and Network Forensics Practice Question
A forensic examiner finds a suspicious entry in the Linux file /etc/passwd: 'backdoor:x:0:0:root:/root:/bin/bash'. What is the MOST significant security issue with this entry?
⚠ Common exam trap
The CHFI exam often tests the misconception that the password hash field or the shell choice is the primary security concern, when in fact the UID of 0 is the critical indicator of root-level access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The UID is 0, granting root privileges
The UID (user ID) of 0 is the root user identifier in Linux. Any account with UID 0 is granted the same privileges as the root user, regardless of the account name. This entry effectively creates a backdoor account with full administrative control over the system, bypassing normal authentication and accountability measures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The entry has no password hash
Why it's wrong here
In /etc/passwd, the second field holds a placeholder; 'x' means the actual password hash is stored in /etc/shadow, which is readable only by root. This is standard practice on modern Linux systems, so the absence of a hash in the passwd entry is not itself a security concern. The backdoor would still require a valid hash in the shadow file, but the 'x' placeholder does not indicate a vulnerability.
- ✗
The home directory is set to /root
Why it's wrong here
A standard user account typically has a home directory under /home, so /root stands out as unusual. However, the home directory path is merely a configuration string and does not convey any privileges. While an attacker might use /root to blend in or simplify environment setup, the directory itself is not what grants root-level access; UID 0 is. Therefore, this anomaly is secondary to the UID finding.
- ✓
The UID is 0, granting root privileges
Why this is correct
In Linux, UID 0 is reserved for root and any process or user with UID 0 bypasses all permission checks. A passwd entry with UID 0 means that logging into that account immediately grants full root control, regardless of the username appearing in the entry. This is a well-known backdoor technique, making it the most critical indicator in the passwd file.
- ✗
The shell is /bin/bash
Why it's wrong here
/bin/bash is the default login shell for most Linux distributions and is commonly assigned to ordinary user accounts. While an interactive shell is useful for an attacker, its presence in a passwd entry does not elevate privileges or indicate malicious activity. The shell field only defines the program launched after login, so it is not a meaningful sign of compromise on its own.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.