Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

An attacker has compromised a Linux server and edited the /etc/passwd file to change a user's UID to 0. What is the likely goal of this modification?

⚠ Common exam trap

A common misconception tested on the EC-CHFI exam is that changing the UID to 0 only affects the user's group or that it is equivalent to adding the user to the root group, when in fact UID 0 grants full root privileges regardless of group membership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To escalate privileges to root

In Linux, the UID 0 is reserved for the root user, who has unrestricted access to the system. By changing a user's UID to 0, the attacker grants that user the same privileges as root, effectively escalating their access to the highest level. This is a classic privilege escalation technique because the kernel identifies root by UID, not by the username.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To lock the user account

    Why it's wrong here

    Locking an account in Linux is done by placing '!' or '*' before the password hash in /etc/shadow, not by changing the UID in /etc/passwd. In fact, setting a user's UID to 0 grants that account root-level rights, which is the exact opposite of locking. A locked account denies all logins, while a UID 0 account is unrestricted and highly dangerous.

  • ✓

    To escalate privileges to root

    Why this is correct

    The attacker changes the UID field to 0 because Linux kernels treat UID 0 as the root superuser and give it unrestricted access to all files, processes, and system calls. When the compromised user logs in, the session adopts that UID and inherits full root capabilities without needing su or sudo. This is a classic privilege‑escalation persistence: the account effectively becomes an alternate root entry.

  • ✗

    To enable password-less login

    Why it's wrong here

    Password-less login means the authentication step can be bypassed, usually via an empty hash in /etc/shadow or an SSH public key in the user's authorized_keys file. Changing a UID to 0 does nothing to suppress password prompts; the account still must authenticate, and only after successful authentication does the UID affect privilege level. Thus, the attacker would still need a valid password, key, or another bypass to use the altered UID.

  • ✗

    To hide the user account from the system

    Why it's wrong here

    Editing the UID to 0 does not hide an account; the entry remains fully visible in /etc/passwd, and commands such as getent passwd, finger, and last still report it normally. Worse, any file or process owned by UID 0 appears as belonging to root in listings, drawing attention to the modified account rather than concealing it. Actual account hiding would require kernel-level rootkit manipulation or log tampering, not a simple passwd file edit.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.