GSEC Linux Security and Hardening Practice Question
A security engineer is configuring a Linux server to enforce password quality for all local accounts. The requirement is that passwords must be at least 14 characters long, contain at least one uppercase letter, one lowercase letter, one digit, and one special character, and must not repeat any of the last 5 passwords. Which file should the engineer edit to enforce these settings?
⚠ Common exam trap
Watch out — candidates often confuse password aging settings in /etc/login.defs with password complexity enforcement, which is handled by PAM and pwquality.conf.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/security/pwquality.conf
Password complexity and history requirements on Linux are enforced by the pam_pwquality module, which reads its configuration from /etc/security/pwquality.conf. This file allows administrators to set minlen, character class requirements, and other constraints. While PAM configuration files like system-auth or common-password reference the module, the policy parameters themselves are defined in pwquality.conf. Therefore, editing /etc/security/pwquality.conf is the correct action to meet the stated password policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/pam.d/login
Why it's wrong here
The /etc/pam.d/login file controls PAM modules used during the login process, such as pam_securetty and pam_nologin, but it is not the primary file for password quality enforcement. Password complexity is typically configured in /etc/pam.d/system-auth (RHEL) or /etc/pam.d/common-password (Debian) using pam_pwquality, and the actual policy parameters reside in /etc/security/pwquality.conf. Editing login alone would not apply the required settings.
- ✗
/etc/login.defs
Why it's wrong here
The /etc/login.defs file controls system-wide defaults for useradd, usermod, and login, such as UID/GID ranges, password aging (PASS_MAX_DAYS), and umask, but it does not enforce password complexity rules like character classes or password history. Those are handled by PAM modules configured in /etc/pam.d/system-auth or /etc/pam.d/common-password. Editing login.defs alone would not meet the requirement for complexity or history.
- ✓
/etc/security/pwquality.conf
Why this is correct
The /etc/security/pwquality.conf file is used by the pam_pwquality PAM module to enforce password complexity requirements such as minimum length (minlen), required character classes (ucredit, lcredit, dcredit, ocredit), and password history via the remember parameter (often set in PAM configuration but also influenced by pwquality). This is the correct location to define the specified password policy for local accounts on modern Linux distributions.
- ✗
/etc/shadow
Why it's wrong here
The /etc/shadow file stores password hashes and aging information for user accounts, including the number of days since the last password change and account expiration. It does not contain policy settings for password complexity or history. Modifying /etc/shadow directly would only affect individual account entries, not enforce system-wide password rules, and is not the correct approach for setting password quality requirements.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.