GCFA Enterprise Environment Incident Response Practice Question
An incident responder is analyzing a Linux server that was compromised. The attacker gained initial access via SSH and then created a new user account named 'support' with UID 0. Which command should the responder use to quickly identify all accounts with UID 0 on the system?
⚠ Common exam trap
The trap here is assuming that only the 'root' account can have UID 0, when in fact any account can be assigned UID 0.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cat /etc/passwd | grep ':0:'
The /etc/passwd file stores user account details, including the UID in the third field. Searching for ':0:' isolates accounts with UID 0, which have root privileges. This quickly uncovers any unauthorized root-equivalent accounts created by an attacker. Other commands like ls, ps, or netstat do not provide UID information and would not detect the malicious account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
netstat -tulpn
Why it's wrong here
The netstat command displays network connections, listening ports, and associated process IDs. It has nothing to do with user accounts or UIDs. While it can be useful for identifying suspicious network services, it will not reveal UID 0 accounts. Therefore, it is not the right command for this scenario.
- ✓
cat /etc/passwd | grep ':0:'
Why this is correct
The /etc/passwd file contains user account information, with fields separated by colons. The third field is the UID. Searching for ':0:' will match any line where the UID is 0, which is typically only root. This command quickly reveals any additional accounts with root privileges, such as the malicious 'support' account. It is a simple and effective way to detect unauthorized UID 0 accounts.
- ✗
ps aux | grep root
Why it's wrong here
The 'ps aux' command lists running processes and their owners, not user accounts. It may show processes running as root, but it does not list all accounts with UID 0. An attacker's account might not have any running processes at the moment, so this would miss it. This command is for process analysis, not account enumeration.
- ✗
ls -la /home
Why it's wrong here
Listing the /home directory shows the home directories of users, but does not display UID information. An attacker could create a UID 0 account without a home directory, or with a home directory elsewhere. This command would not reveal the UID, so it cannot identify accounts with UID 0. It is not the correct tool for this purpose.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.