Courseiva
Linux Fundamentals →mediumMultiple Choice

GSEC Linux Fundamentals Practice Question

A security analyst is examining a Linux system for signs of compromise. The analyst notices that a suspicious process is running with a parent process ID (PPID) of 1. Which command will display the process tree, showing parent-child relationships, to help identify how the process was launched?

⚠ Common exam trap

The trap here is assuming that ps -ef provides a tree view because it includes PPID, when it actually presents a flat list that requires manual correlation to understand process ancestry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

pstree -p

The pstree -p command provides a visual tree of processes with PIDs, making it straightforward to trace parent-child relationships. This is particularly useful when investigating a suspicious process whose PPID is 1, as it helps determine whether the process was legitimately started by init or if it was orphaned or injected. Other commands lack the hierarchical view needed for this analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pgrep -l suspicious

    Why it's wrong here

    The pgrep command searches for processes by name and returns their PIDs. With -l, it also lists the process names. However, it does not show parent-child relationships or the process tree. It would only confirm the PID of the suspicious process, not how it was launched or its ancestry, which is the analyst's goal.

  • ✓

    pstree -p

    Why this is correct

    The pstree command displays running processes as a tree, visually showing parent-child relationships. The -p option includes PIDs, making it easy to correlate with the suspicious process. This helps the analyst quickly identify the ancestry of the process, such as whether it was spawned by init (PID 1) or another parent, which is crucial for understanding how it was launched.

  • ✗

    top -H

    Why it's wrong here

    The top -H command displays individual threads instead of processes, showing thread-level CPU usage. It does not provide a hierarchical view of processes or clearly show parent-child relationships. While top can show PPID in some configurations, it is not designed for tree visualization and would not efficiently reveal the process ancestry needed for the investigation.

  • ✗

    ps -ef

    Why it's wrong here

    The ps -ef command lists all processes in a flat format, showing UID, PID, PPID, C, STIME, TTY, TIME, and CMD. While it includes PPID, it does not visually represent the hierarchical parent-child relationships, making it harder to trace the process tree. For a clear tree view, a command like pstree or ps with forest option is more appropriate.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.