Courseiva

GSEC Access Control and Password Management Practice Question

A security administrator is configuring a Linux server and needs to enforce that all user passwords are hashed with a strong, salted algorithm. Which file should the administrator edit to set the default password hashing algorithm for new passwords?

⚠ Common exam trap

The trap here is assuming that the password hash file (/etc/shadow) or PAM configuration is where the default algorithm is set, when it is actually in /etc/login.defs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/login.defs

The /etc/login.defs file contains the ENCRYPT_METHOD setting, which specifies the default password hashing algorithm for new passwords on many Linux distributions. Editing this file allows the administrator to enforce a strong, salted algorithm like SHA512. While /etc/shadow stores hashes and PAM configures authentication, the default algorithm is set in login.defs. Therefore, this is the correct file to edit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/pam.d/common-password

    Why it's wrong here

    /etc/pam.d/common-password is a PAM configuration file that controls how password changes are handled, including which pam_unix options are used. While it can influence hashing, the default algorithm is typically set via ENCRYPT_METHOD in /etc/login.defs. On some systems, PAM may override, but the primary system-wide default is in login.defs. Thus, this is not the best answer for setting the default algorithm.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd stores user account information but not password hashes; it typically contains a placeholder 'x' in the password field. Editing it does not change the hashing algorithm. It is used for user identification, not authentication configuration. Therefore, it is not the correct file to set the default password hashing algorithm.

  • ✗

    /etc/shadow

    Why it's wrong here

    /etc/shadow stores the actual password hashes and aging information. While it contains the hashes, it is not where the default hashing algorithm is configured. Modifying it directly could break authentication. The algorithm is set in the PAM configuration, not in the shadow file itself. So this is not the correct answer.

  • ✓

    /etc/login.defs

    Why this is correct

    /etc/login.defs contains configuration settings for the shadow password suite, including the ENCRYPT_METHOD variable, which defines the default password hashing algorithm (e.g., SHA512). Editing this file allows the administrator to enforce a strong, salted algorithm for new passwords. This is the correct file because it controls system-wide password policy defaults.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.