Courseiva
Linux Fundamentals →mediumMultiple Choice

GSEC Linux Fundamentals Practice Question

A security analyst needs to determine which network ports are currently listening for incoming connections on a Linux server. Which command is best suited for this task?

⚠ Common exam trap

Candidates often select deprecated commands like 'netstat' or incomplete commands like 'ps', ignoring modern socket statistics utilities like 'ss' that display listening ports efficiently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ss -tulpn

Identifying open ports is a critical step in reducing the attack surface of a Linux server. The 'ss' (socket statistics) command is the modern, high-performance replacement for the deprecated 'netstat'. It provides detailed information about active connections, listening ports, and the associated process IDs, helping administrators quickly spot unauthorized services that might serve as entry points for malicious actors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ss -tulpn

    Why this is correct

    The ss command with these flags displays all TCP and UDP listening ports, along with the numeric service port and the process ID (PID) that opened the port. This level of detail is vital for security professionals to map open network sockets back to specific running applications.

  • ✗

    ifconfig -a

    Why it's wrong here

    The ifconfig command displays network interface configuration details, such as IP addresses, subnet masks, and MAC addresses. It does not provide any information about active network connections, listening ports, or the services running on the system, making it useless for identifying open network services.

  • ✗

    ping -c 5 localhost

    Why it's wrong here

    The ping command tests network connectivity between the current host and a destination. It is a diagnostic tool for checking path availability and latency, not for enumerating services or listening ports on the local system. It will not reveal any information regarding the state of network applications.

  • ✗

    dig @localhost

    Why it's wrong here

    The dig command is a DNS lookup utility used to query DNS servers. It is strictly focused on domain name resolution and provides no insight into the system's listening network ports or active connections. Using this will only confirm DNS configuration, not the system's network attack surface.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.