Courseiva
Linux Fundamentals →hardMultiple Choice

GSEC Linux Fundamentals Practice Question

A security analyst is investigating a compromised Linux server and wants to examine the environment variables of a running process with PID 1234 to identify potential injected malicious variables. Which command will display the environment of that specific process?

⚠ Common exam trap

The trap here is assuming that process listing commands like ps or env can show another process's environment, when only /proc/PID/environ provides that data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cat /proc/1234/environ

To inspect the environment of a running process, the analyst can read /proc/PID/environ. This pseudo-file contains the environment variables as a null-delimited string, reflecting the process's initial environment. Tools like ps and lsof provide other process details but not environment. The env command only shows the current shell's environment. Thus, accessing /proc/1234/environ is the correct approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ps aux | grep 1234

    Why it's wrong here

    The 'ps aux' command lists processes with details like user, CPU, and memory usage, but it does not display environment variables. Even when filtered for a specific PID, it only shows the command line and basic attributes. It cannot reveal the environment, so it fails to meet the analyst's requirement.

  • ✗

    env

    Why it's wrong here

    The 'env' command prints the environment variables of the current shell, not of an arbitrary running process. It would show the analyst's own environment, which is unrelated to PID 1234. Without options or privileges, env cannot target another process, making it unsuitable for this investigation.

  • ✓

    cat /proc/1234/environ

    Why this is correct

    The /proc filesystem exposes process information. /proc/1234/environ contains the environment variables of process 1234 as a null-separated list. Reading this file reveals the exact environment the process was started with, which can help detect injected variables. It is the direct and correct method to inspect a specific process's environment.

  • ✗

    lsof -p 1234

    Why it's wrong here

    lsof lists open files for a process, including regular files, sockets, and libraries. While it can show which files PID 1234 has open, it does not display environment variables. The analyst would not find injected variables through lsof, so this command does not fulfill the specific need.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.