Courseiva

GSEC Linux Security and Hardening Practice Question

A security administrator is hardening the boot process of a production Ubuntu 22.04 server that uses GRUB 2. The policy requires that any interactive modification to the kernel command line at the GRUB menu must be blocked, and that the bootloader configuration file must be unreadable by unprivileged users. Which action should the administrator take to meet these requirements?

⚠ Common exam trap

The trap here is assuming that hiding the GRUB menu or enabling Secure Boot alone prevents kernel command-line tampering, when only a GRUB superuser password actually blocks interactive edits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run grub-mkpasswd-pbkdf2, add a superuser entry with the resulting hash to /etc/grub.d/40_custom, and set chmod 600 on /boot/grub/grub.cfg.

Blocking interactive GRUB edits requires a bootloader password so the menu cannot be modified without authentication, and protecting grub.cfg with restrictive permissions prevents unprivileged users from reading boot parameters. The other choices either only hide the menu, rely on firmware verification that does not restrict menu editing, or introduce a recovery parameter that reduces security. Together, the password and file permission changes satisfy both parts of the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the UEFI Secure Boot option in firmware and reinstall the operating system with a signed kernel.

    Why it's wrong here

    Secure Boot verifies the signature of boot components and can prevent unsigned kernels or bootloaders from running, but it does not stop an authorized user from editing the kernel command line at the GRUB menu when the bootloader itself is trusted. It also does not change the permissions on grub.cfg. Therefore it does not meet the requirement to block interactive boot edits or protect the config file.

  • ✓

    Run grub-mkpasswd-pbkdf2, add a superuser entry with the resulting hash to /etc/grub.d/40_custom, and set chmod 600 on /boot/grub/grub.cfg.

    Why this is correct

    Password-protecting the GRUB 2 menu with a superuser entry prevents interactive editing of kernel parameters at boot, and restricting permissions on grub.cfg blocks unprivileged reading of the bootloader configuration. Together these satisfy the stated hardening policy, because only users who supply the GRUB password can modify boot entries, and other local users cannot inspect the configuration file.

  • ✗

    Set GRUB_TIMEOUT=0 in /etc/default/grub and run update-grub to hide the menu.

    Why it's wrong here

    Setting the boot menu timeout to zero hides the menu during normal boots, but it does not prevent an attacker from interrupting the boot sequence (for example by holding Shift) and editing the kernel line. It also does nothing to protect the contents of grub.cfg from local users. This control only improves the appearance and speed of boot, not the integrity of the bootloader configuration.

  • ✗

    Add the kernel parameter init=/bin/bash to /etc/default/grub and regenerate the bootloader configuration.

    Why it's wrong here

    Setting init=/bin/bash changes the init process that the kernel starts, which would give a shell without normal service startup. This weakens security rather than hardening it, and it does nothing to restrict menu editing or file permissions. It is a common recovery technique, not a protective control, so it directly contradicts the stated policy.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.