Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic examiner finds a suspicious entry in the Linux file /etc/passwd: 'backdoor:x:0:0:root:/root:/bin/bash'. What is the MOST significant security issue with this entry?

⚠ Common exam trap

The CHFI exam often tests the misconception that the password hash field or the shell choice is the primary security concern, when in fact the UID of 0 is the critical indicator of root-level access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The UID is 0, granting root privileges

The UID (user ID) of 0 is the root user identifier in Linux. Any account with UID 0 is granted the same privileges as the root user, regardless of the account name. This entry effectively creates a backdoor account with full administrative control over the system, bypassing normal authentication and accountability measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The entry has no password hash

    Why it's wrong here

    In /etc/passwd, the second field holds a placeholder; 'x' means the actual password hash is stored in /etc/shadow, which is readable only by root. This is standard practice on modern Linux systems, so the absence of a hash in the passwd entry is not itself a security concern. The backdoor would still require a valid hash in the shadow file, but the 'x' placeholder does not indicate a vulnerability.

  • ✗

    The home directory is set to /root

    Why it's wrong here

    A standard user account typically has a home directory under /home, so /root stands out as unusual. However, the home directory path is merely a configuration string and does not convey any privileges. While an attacker might use /root to blend in or simplify environment setup, the directory itself is not what grants root-level access; UID 0 is. Therefore, this anomaly is secondary to the UID finding.

  • ✓

    The UID is 0, granting root privileges

    Why this is correct

    In Linux, UID 0 is reserved for root and any process or user with UID 0 bypasses all permission checks. A passwd entry with UID 0 means that logging into that account immediately grants full root control, regardless of the username appearing in the entry. This is a well-known backdoor technique, making it the most critical indicator in the passwd file.

  • ✗

    The shell is /bin/bash

    Why it's wrong here

    /bin/bash is the default login shell for most Linux distributions and is commonly assigned to ordinary user accounts. While an interactive shell is useful for an attacker, its presence in a passwd entry does not elevate privileges or indicate malicious activity. The shell field only defines the program launched after login, so it is not a meaningful sign of compromise on its own.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.