CHFI OS and Network Forensics Practice Question
An attacker has compromised a Linux server and edited the /etc/passwd file to change a user's UID to 0. What is the likely goal of this modification?
⚠ Common exam trap
A common misconception tested on the EC-CHFI exam is that changing the UID to 0 only affects the user's group or that it is equivalent to adding the user to the root group, when in fact UID 0 grants full root privileges regardless of group membership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To escalate privileges to root
In Linux, the UID 0 is reserved for the root user, who has unrestricted access to the system. By changing a user's UID to 0, the attacker grants that user the same privileges as root, effectively escalating their access to the highest level. This is a classic privilege escalation technique because the kernel identifies root by UID, not by the username.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To lock the user account
Why it's wrong here
Locking an account in Linux is done by placing '!' or '*' before the password hash in /etc/shadow, not by changing the UID in /etc/passwd. In fact, setting a user's UID to 0 grants that account root-level rights, which is the exact opposite of locking. A locked account denies all logins, while a UID 0 account is unrestricted and highly dangerous.
- ✓
To escalate privileges to root
Why this is correct
The attacker changes the UID field to 0 because Linux kernels treat UID 0 as the root superuser and give it unrestricted access to all files, processes, and system calls. When the compromised user logs in, the session adopts that UID and inherits full root capabilities without needing su or sudo. This is a classic privilege‑escalation persistence: the account effectively becomes an alternate root entry.
- ✗
To enable password-less login
Why it's wrong here
Password-less login means the authentication step can be bypassed, usually via an empty hash in /etc/shadow or an SSH public key in the user's authorized_keys file. Changing a UID to 0 does nothing to suppress password prompts; the account still must authenticate, and only after successful authentication does the UID affect privilege level. Thus, the attacker would still need a valid password, key, or another bypass to use the altered UID.
- ✗
To hide the user account from the system
Why it's wrong here
Editing the UID to 0 does not hide an account; the entry remains fully visible in /etc/passwd, and commands such as getent passwd, finger, and last still report it normally. Worse, any file or process owned by UID 0 appears as belonging to root in listings, drawing attention to the modified account rather than concealing it. Actual account hiding would require kernel-level rootkit manipulation or log tampering, not a simple passwd file edit.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.