Courseiva

GSEC · domain

Linux Fundamentals

GSEC Linux Fundamentals covers file permissions, process and log inspection, and privilege-escalation artifacts on Linux hosts. Questions are scenario-based: you are given a command or a symptom and must choose the correct command, interpret its output, or explain the security implication. Expect chmod/chown, setuid/setgid, tail/less, lsof, and log-file handling to appear in practical, tool-oriented form.

13 questions3 easy6 medium4 hard

Focused practice

Practice Linux Fundamentals questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Linux Fundamentals

Be able to read a permission string, run chmod/chown correctly, follow logs with tail -f, and audit setuid files and open file handles with find and lsof. The key skill is interpreting command output to decide whether access or privilege behavior is expected or suspicious.

Applying chmod symbolic and octal modes to restrict read, write, and execute per owner, group, and other.

Using tail -f and less +F to follow log files such as /var/log/auth.log in real time.

Identifying setuid/setgid binaries with find -perm and assessing root-owned custom executables.

Interpreting lsof output for deleted-but-open files, including unlinked logs held by a process.

Watch out for

Common Linux Fundamentals exam traps

  • ▸Confusing chmod permission bits with ownership changes; chmod cannot alter owner, only chown does.
  • ▸Assuming a deleted file is gone: lsof shows unlinked files still held open by a running process.
  • ▸Treating every setuid root binary as malicious; standard tools like passwd legitimately need setuid.

Question index

All Linux Fundamentals questions (13)

Click any question to see the full explanation, or start a practice session above.

1

A security analyst is investigating a compromised Linux server and wants to examine the environment variables of a running process with PID 1234 to identify potential injected malicious variables. Which command will display the environment of that specific process?

Hard
2

A security analyst is examining a Linux system for signs of compromise. The analyst notices that a suspicious process is running with a parent process ID (PPID) of 1. Which command will display the process tree, showing parent-child relationships, to help identify how the process was launched?

Medium
3

A Linux administrator needs to identify which processes are currently consuming the most CPU resources. Which command provides an interactive, real-time view of system performance and process activity?

Easy
4

A security analyst needs to determine which network ports are currently listening for incoming connections on a Linux server. Which command is best suited for this task?

Medium
5

Refer to the exhibit. A user attempts to delete a file located inside '/opt/backup', but the operation fails with a 'Permission denied' error. Given the directory permissions shown, what is the most likely cause?

Hard
6

A junior administrator needs to determine the default gateway configured on a Linux server to troubleshoot outbound connectivity. Which command will display the routing table and show the default route?

Easy
7

A Linux server has the setuid bit set on /usr/bin/passwd. A security engineer notices that a custom binary /opt/tools/backup_tool also has the setuid bit set and is owned by root. The engineer wants to determine whether executing backup_tool will run with root privileges regardless of which user invokes it. Which of the following is the most accurate statement about how the setuid bit affects process credentials on Linux?

Hard
8

An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?

Medium
9

A security administrator is hardening a Linux web server. The administrator needs to ensure that the Apache service, which runs as the user 'www-data', cannot be used to escalate privileges if compromised. Which file should the administrator check to verify that 'www-data' does not have a valid login shell?

Easy
10

A security analyst is investigating a suspicious file on a Linux server. The analyst wants to determine the file's inode number, permissions, owner, group, size, and last modification time without modifying the file. Which command should the analyst use?

Hard
11

A security administrator is hardening a Linux server and needs to ensure that user passwords meet complexity requirements and are stored securely. Which two actions should the administrator take? (Choose two.)

Medium
12

A security analyst is reviewing a compromised Linux web server. The attacker escalated to root and then ran a script that unlinked the file /var/log/auth.log to hide their tracks. The analyst runs `lsof | grep auth.log` and sees the file is still open by the rsyslogd process, but `ls /var/log/auth.log` reports that the file does not exist. Which of the following best explains why the file content is still accessible through the open file descriptor?

Medium
13

A security administrator needs to ensure that a newly created script, 'cleanup.sh', can only be executed by the file owner, while preventing any other users from reading or writing the file. Which command achieves this configuration?

Medium

Frequently asked questions

What does the Linux Fundamentals domain cover on the GSEC exam?
Be able to read a permission string, run chmod/chown correctly, follow logs with tail -f, and audit setuid files and open file handles with find and lsof. The key skill is interpreting command output to decide whether access or privilege behavior is expected or suspicious.
How many questions are in this domain?
This page lists all 13 Linux Fundamentals questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Linux Fundamentals questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC linux fundamentals Practice Questions