GSEC Linux Fundamentals Practice Question
A security analyst is investigating a compromised Linux server and wants to examine the environment variables of a running process with PID 1234 to identify potential injected malicious variables. Which command will display the environment of that specific process?
⚠ Common exam trap
The trap here is assuming that process listing commands like ps or env can show another process's environment, when only /proc/PID/environ provides that data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cat /proc/1234/environ
To inspect the environment of a running process, the analyst can read /proc/PID/environ. This pseudo-file contains the environment variables as a null-delimited string, reflecting the process's initial environment. Tools like ps and lsof provide other process details but not environment. The env command only shows the current shell's environment. Thus, accessing /proc/1234/environ is the correct approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ps aux | grep 1234
Why it's wrong here
The 'ps aux' command lists processes with details like user, CPU, and memory usage, but it does not display environment variables. Even when filtered for a specific PID, it only shows the command line and basic attributes. It cannot reveal the environment, so it fails to meet the analyst's requirement.
- ✗
env
Why it's wrong here
The 'env' command prints the environment variables of the current shell, not of an arbitrary running process. It would show the analyst's own environment, which is unrelated to PID 1234. Without options or privileges, env cannot target another process, making it unsuitable for this investigation.
- ✓
cat /proc/1234/environ
Why this is correct
The /proc filesystem exposes process information. /proc/1234/environ contains the environment variables of process 1234 as a null-separated list. Reading this file reveals the exact environment the process was started with, which can help detect injected variables. It is the direct and correct method to inspect a specific process's environment.
- ✗
lsof -p 1234
Why it's wrong here
lsof lists open files for a process, including regular files, sockets, and libraries. While it can show which files PID 1234 has open, it does not display environment variables. The analyst would not find injected variables through lsof, so this command does not fulfill the specific need.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.