GSEC Linux Security and Hardening Practice Question
A system administrator is hardening a Linux server and wants to ensure that users cannot log in with empty passwords. Which command should the administrator use to check for accounts with empty password fields in /etc/shadow?
⚠ Common exam trap
The trap here is using a command that checks for password status via passwd -S, which is slower and may not work for all accounts, instead of directly inspecting the shadow file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
awk -F: '($2 == "") {print $1}' /etc/shadow
To identify accounts with empty passwords, the most direct method is to parse /etc/shadow and check if the password hash field is empty. The awk command with field separator ':' and condition $2 == "" accomplishes this by printing the username for any line where the second field is empty. This is a common security audit technique. Other methods may work but are less precise or efficient. Ensuring no accounts have empty passwords is a fundamental Linux hardening step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
cut -d: -f1,2 /etc/shadow | grep ':$'
Why it's wrong here
This command extracts the first two fields (username and password hash) and then greps for lines ending with a colon, which would indicate an empty second field. However, because it uses cut with -f1,2, the output is 'username:hash', and if the hash is empty, the line ends with a colon. This works, but it is less direct than using awk to check the second field. It also may include the colon from the cut output, but the logic is sound. However, it is not the most standard or efficient method, and could be confusing.
- ✗
passwd -S $(cut -d: -f1 /etc/shadow) | grep 'NP'
Why it's wrong here
The passwd -S command displays password status for a user, where 'NP' indicates no password. However, running passwd -S for every user in /etc/shadow is inefficient and may produce errors for system accounts. It also requires root privileges and may not work for all accounts. While it can detect empty passwords, it is not a direct file audit and is more complex than necessary. The awk method is simpler and more reliable.
- ✗
grep -v '^[^:]*:[^:]*:' /etc/shadow
Why it's wrong here
This grep command attempts to find lines that do not match a pattern of at least two colon-separated fields. However, the pattern is flawed: it would match lines that have fewer than two fields, but /etc/shadow always has multiple fields. It does not specifically target empty password fields. It may produce false positives or miss the intended accounts. A more direct approach is needed to check for empty second fields.
- ✓
awk -F: '($2 == "") {print $1}' /etc/shadow
Why this is correct
This awk command parses /etc/shadow using colon as the field separator and checks if the second field (the password hash) is empty. If so, it prints the username. This directly identifies accounts with empty passwords, which is a critical security risk. It is a precise and efficient way to audit for this specific misconfiguration.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.