Courseiva

GSEC Linux Security and Hardening Practice Question

A security administrator is configuring auditd on a Linux server to meet a compliance requirement that all changes to user and group files be logged. The administrator adds a watch on /etc/passwd and /etc/group. After applying the rules, the administrator notices that modifications made using the 'vipw' and 'vigr' commands are not generating audit events, even though direct edits with a text editor are logged. Which explanation best describes why this occurs?

⚠ Common exam trap

The trap here is assuming that a file watch follows the filename, when auditd actually binds the watch to the file's inode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

vipw and vigr use a temporary file and rename it over the original, so a file watch on /etc/passwd sees a different inode and misses the change.

Audit watches in auditd are bound to the inode of the target file. The vipw and vigr utilities create a temporary file and rename it over the original, so the original inode is replaced and the watch no longer covers the new file. Direct edits modify the existing inode and are logged. To reliably capture these changes, administrators should watch the containing directory or use audit rules that account for renames.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vipw and vigr run as setuid root and bypass the kernel audit subsystem entirely, so no audit rules can capture their activity.

    Why it's wrong here

    The kernel audit subsystem captures system calls regardless of whether a process is setuid; setuid status does not exempt a process from auditing. The real reason vipw and vigr evade a file watch is the inode replacement via rename, not a bypass of the audit subsystem. This explanation mischaracterizes how auditd interacts with privileged processes.

  • ✗

    The audit rules were not loaded because auditd requires a reboot after adding watches to /etc/passwd and /etc/group.

    Why it's wrong here

    Audit rules can be loaded at runtime with augenrules --load or auditctl, and direct edits are being logged, which proves the rules are active. A reboot is not required for watches to take effect. Since some modifications are captured, the rule loading is not the cause of the missing vipw and vigr events.

  • ✓

    vipw and vigr use a temporary file and rename it over the original, so a file watch on /etc/passwd sees a different inode and misses the change.

    Why this is correct

    Audit watches are attached to the inode of the watched file. Tools like vipw and vigr edit a temporary copy and then rename it over the original, creating a new inode. The watch on the old inode no longer applies, so the modification is not logged. This is a well-known limitation that requires watching the directory or using a different audit key strategy.

  • ✗

    vipw and vigr write to /etc/shadow and /etc/gshadow instead of /etc/passwd and /etc/group, so the watches never trigger.

    Why it's wrong here

    vipw edits /etc/passwd and vigr edits /etc/group, though they may also update the corresponding shadow files for password changes. The absence of audit events is not because they write elsewhere; it is because they replace the file via rename, changing the inode that the watch is bound to. This option misstates the file targets.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.