GSEC Linux Fundamentals Practice Question
A security administrator is hardening a Linux web server. The administrator needs to ensure that the Apache service, which runs as the user 'www-data', cannot be used to escalate privileges if compromised. Which file should the administrator check to verify that 'www-data' does not have a valid login shell?
⚠ Common exam trap
Many exam-takers confuse the purpose of /etc/shadow with that of /etc/passwd, assuming that password-related security settings are found in the same file as shell assignments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/passwd
The login shell for a user is stored in the seventh field of /etc/passwd. Service accounts like 'www-data' should have a non-interactive shell such as /usr/sbin/nologin to prevent attackers from obtaining a shell if the service is compromised. Other files contain password hashes, group data, or sudo rules, but none store the login shell assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/sudoers
Why it's wrong here
The /etc/sudoers file controls which users and groups can run commands with elevated privileges via sudo. It does not define login shells. Although checking sudoers is part of hardening, it does not indicate whether 'www-data' has a valid shell. Therefore, it does not fulfill the requirement to verify the absence of a login shell for that service account.
- ✗
/etc/group
Why it's wrong here
The /etc/group file defines group memberships, listing group names, passwords, GIDs, and member users. It does not contain login shell information for individual users. While group memberships are relevant to privilege auditing, they do not answer the question of whether 'www-data' has a valid login shell, making this file unsuitable for the administrator's specific goal.
- ✗
/etc/shadow
Why it's wrong here
The /etc/shadow file stores encrypted password hashes and password aging information, not login shells. While it is important for auditing password security, it does not contain the shell assignment for user accounts. Checking /etc/shadow would not reveal whether 'www-data' has a valid login shell, so it is not the correct file for this task.
- ✓
/etc/passwd
Why this is correct
The /etc/passwd file contains the login shell for each user in its seventh field. By checking this file, the administrator can verify that the 'www-data' account has a non-login shell such as /usr/sbin/nologin or /bin/false, which prevents interactive logins and reduces privilege escalation risk if the service is compromised.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.