GCFA Practice Question: Identification of Malicious and Normal Activity
While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?
⚠ Common exam trap
The trap here is trusting the process name alone, when on Linux the parent PID and bound sockets are what distinguish a real daemon from a masqueraded binary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker renamed a malicious binary to 'sshd' to blend in with legitimate processes.
On Linux, parent process and socket state are strong discriminators of legitimacy. A real sshd is started by systemd, which makes PID 1 its parent, and it binds port 22. A process carrying the sshd name but parented by bash and holding no listening socket could not be performing the SSH service role, so the most supportable conclusion is that a binary was renamed to mimic sshd.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An attacker renamed a malicious binary to 'sshd' to blend in with legitimate processes.
Why this is correct
Legitimate sshd is spawned by systemd and immediately opens its listening socket on port 22. A process named sshd but parented by bash and holding no listener was almost certainly started manually by an interactive shell, which is the hallmark of an attacker renaming a tool to masquerade as a system daemon while it performs other actions such as beaconing or credential collection.
- ✗
The sshd binary was updated by the package manager during an unattended upgrade.
Why it's wrong here
Package upgrades replace the on-disk binary and restart the service under systemd, so the parent would remain PID 1 and the process would still bind port 22. A bash parent with no listening socket is inconsistent with a package-driven restart, because the service manager would own the process lifecycle and the daemon would re-establish its listener immediately after start.
- ✗
The sshd process is a legitimate child spawned by a user's SSH session.
Why it's wrong here
Per-session sshd children are forked by the master daemon, so their parent is the master sshd, not bash, and they communicate over an already established connection rather than binding a new listener. A process with a bash parent and no socket cannot be a session handler, because session handlers inherit the listening socket and are chained to the master daemon process tree.
- ✗
The system experienced a crash and systemd restarted sshd through a recovery shell.
Why it's wrong here
systemd restarts units directly and the restarted sshd would again be a child of PID 1 with its listening socket reopened. A recovery shell session would not leave a bash parent attached to the long-running daemon, and the absence of a listening socket means the process is not functioning as the SSH service at all, so a crash-recovery explanation does not fit.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.