GSEC Linux Fundamentals Practice Question
A security analyst is examining a Linux system for signs of compromise. The analyst notices that a suspicious process is running with a parent process ID (PPID) of 1. Which command will display the process tree, showing parent-child relationships, to help identify how the process was launched?
⚠ Common exam trap
The trap here is assuming that ps -ef provides a tree view because it includes PPID, when it actually presents a flat list that requires manual correlation to understand process ancestry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pstree -p
The pstree -p command provides a visual tree of processes with PIDs, making it straightforward to trace parent-child relationships. This is particularly useful when investigating a suspicious process whose PPID is 1, as it helps determine whether the process was legitimately started by init or if it was orphaned or injected. Other commands lack the hierarchical view needed for this analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
pgrep -l suspicious
Why it's wrong here
The pgrep command searches for processes by name and returns their PIDs. With -l, it also lists the process names. However, it does not show parent-child relationships or the process tree. It would only confirm the PID of the suspicious process, not how it was launched or its ancestry, which is the analyst's goal.
- ✓
pstree -p
Why this is correct
The pstree command displays running processes as a tree, visually showing parent-child relationships. The -p option includes PIDs, making it easy to correlate with the suspicious process. This helps the analyst quickly identify the ancestry of the process, such as whether it was spawned by init (PID 1) or another parent, which is crucial for understanding how it was launched.
- ✗
top -H
Why it's wrong here
The top -H command displays individual threads instead of processes, showing thread-level CPU usage. It does not provide a hierarchical view of processes or clearly show parent-child relationships. While top can show PPID in some configurations, it is not designed for tree visualization and would not efficiently reveal the process ancestry needed for the investigation.
- ✗
ps -ef
Why it's wrong here
The ps -ef command lists all processes in a flat format, showing UID, PID, PPID, C, STIME, TTY, TIME, and CMD. While it includes PPID, it does not visually represent the hierarchical parent-child relationships, making it harder to trace the process tree. For a clear tree view, a command like pstree or ps with forest option is more appropriate.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.