Courseiva
Linux Fundamentals →easyMultiple Choice

GSEC Linux Fundamentals Practice Question

A security administrator is hardening a Linux web server. The administrator needs to ensure that the Apache service, which runs as the user 'www-data', cannot be used to escalate privileges if compromised. Which file should the administrator check to verify that 'www-data' does not have a valid login shell?

⚠ Common exam trap

Many exam-takers confuse the purpose of /etc/shadow with that of /etc/passwd, assuming that password-related security settings are found in the same file as shell assignments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/passwd

The login shell for a user is stored in the seventh field of /etc/passwd. Service accounts like 'www-data' should have a non-interactive shell such as /usr/sbin/nologin to prevent attackers from obtaining a shell if the service is compromised. Other files contain password hashes, group data, or sudo rules, but none store the login shell assignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/sudoers

    Why it's wrong here

    The /etc/sudoers file controls which users and groups can run commands with elevated privileges via sudo. It does not define login shells. Although checking sudoers is part of hardening, it does not indicate whether 'www-data' has a valid shell. Therefore, it does not fulfill the requirement to verify the absence of a login shell for that service account.

  • ✗

    /etc/group

    Why it's wrong here

    The /etc/group file defines group memberships, listing group names, passwords, GIDs, and member users. It does not contain login shell information for individual users. While group memberships are relevant to privilege auditing, they do not answer the question of whether 'www-data' has a valid login shell, making this file unsuitable for the administrator's specific goal.

  • ✗

    /etc/shadow

    Why it's wrong here

    The /etc/shadow file stores encrypted password hashes and password aging information, not login shells. While it is important for auditing password security, it does not contain the shell assignment for user accounts. Checking /etc/shadow would not reveal whether 'www-data' has a valid login shell, so it is not the correct file for this task.

  • ✓

    /etc/passwd

    Why this is correct

    The /etc/passwd file contains the login shell for each user in its seventh field. By checking this file, the administrator can verify that the 'www-data' account has a non-login shell such as /usr/sbin/nologin or /bin/false, which prevents interactive logins and reduces privilege escalation risk if the service is compromised.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.