GSEC Linux Fundamentals Practice Question
A security administrator is hardening a Linux server and needs to ensure that user passwords meet complexity requirements and are stored securely. Which two actions should the administrator take? (Choose two.)
⚠ Common exam trap
The trap here is thinking that password hashing algorithm changes alone enforce complexity, when complexity is actually handled by PAM modules like pam_pwquality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure /etc/shadow is readable only by root and the shadow group.
To enforce password complexity, the administrator should configure pam_pwquality, which provides configurable checks for length, character classes, and dictionary words. To secure password storage, the administrator must ensure /etc/shadow is properly permissioned so that only root and the shadow group can read it, protecting hashes from unauthorized access. Other options either weaken security or do not address the specific requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable password aging by setting PASS_MAX_DAYS to 99999.
Why it's wrong here
Disabling password aging by setting a very high maximum days value reduces security by allowing passwords to remain unchanged indefinitely. While it might improve usability, it does not enforce complexity or secure storage. The requirement is to ensure complexity and secure storage, not to remove expiration, so this action is counterproductive to hardening.
- ✗
Store passwords in /etc/passwd instead of /etc/shadow to simplify management.
Why it's wrong here
/etc/passwd is world-readable, so storing password hashes there would expose them to any user, enabling offline cracking. Modern Linux systems use /etc/shadow precisely to restrict access. Moving hashes back to /etc/passwd would severely weaken security and is not a valid hardening action.
- ✓
Ensure /etc/shadow is readable only by root and the shadow group.
Why this is correct
/etc/shadow stores password hashes and must be protected from unauthorized reading. Setting permissions to 640 or 000 with root ownership prevents non-privileged users from accessing hashes, mitigating offline cracking. This is a fundamental security measure for secure password storage. It complements complexity policies by protecting the stored hashes.
- ✗
Set the password hashing algorithm to SHA-256 in /etc/login.defs.
Why it's wrong here
While /etc/login.defs contains some password aging parameters, the hashing algorithm is typically controlled by the ENCRYPT_METHOD variable, but stronger algorithms like yescrypt or SHA-512 are preferred. SHA-256 is not the recommended default and may not be supported directly. Moreover, this does not enforce complexity, so it does not satisfy the requirement.
- ✓
Configure PAM with pam_pwquality to enforce minimum length and character classes.
Why this is correct
pam_pwquality is the PAM module that enforces password complexity policies such as minimum length, character diversity, and dictionary checks. Configuring it in /etc/pam.d/common-password (or system-auth) ensures that password changes adhere to the defined policy. This directly addresses the requirement for complexity and is a standard hardening step on modern Linux systems.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.