Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An incident responder is analyzing a Linux server that was compromised. The attacker gained initial access via SSH and then created a new user account named 'support' with UID 0. Which command should the responder use to quickly identify all accounts with UID 0 on the system?

⚠ Common exam trap

The trap here is assuming that only the 'root' account can have UID 0, when in fact any account can be assigned UID 0.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cat /etc/passwd | grep ':0:'

The /etc/passwd file stores user account details, including the UID in the third field. Searching for ':0:' isolates accounts with UID 0, which have root privileges. This quickly uncovers any unauthorized root-equivalent accounts created by an attacker. Other commands like ls, ps, or netstat do not provide UID information and would not detect the malicious account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    netstat -tulpn

    Why it's wrong here

    The netstat command displays network connections, listening ports, and associated process IDs. It has nothing to do with user accounts or UIDs. While it can be useful for identifying suspicious network services, it will not reveal UID 0 accounts. Therefore, it is not the right command for this scenario.

  • ✓

    cat /etc/passwd | grep ':0:'

    Why this is correct

    The /etc/passwd file contains user account information, with fields separated by colons. The third field is the UID. Searching for ':0:' will match any line where the UID is 0, which is typically only root. This command quickly reveals any additional accounts with root privileges, such as the malicious 'support' account. It is a simple and effective way to detect unauthorized UID 0 accounts.

  • ✗

    ps aux | grep root

    Why it's wrong here

    The 'ps aux' command lists running processes and their owners, not user accounts. It may show processes running as root, but it does not list all accounts with UID 0. An attacker's account might not have any running processes at the moment, so this would miss it. This command is for process analysis, not account enumeration.

  • ✗

    ls -la /home

    Why it's wrong here

    Listing the /home directory shows the home directories of users, but does not display UID information. An attacker could create a UID 0 account without a home directory, or with a home directory elsewhere. This command would not reveal the UID, so it cannot identify accounts with UID 0. It is not the correct tool for this purpose.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.