Courseiva

CCNA Linux Fundamentals Questions

13 questions · Linux Fundamentals · All types, answers revealed

1
MCQhard

A security analyst is investigating a compromised Linux server and wants to examine the environment variables of a running process with PID 1234 to identify potential injected malicious variables. Which command will display the environment of that specific process?

A.ps aux | grep 1234
B.env
C.cat /proc/1234/environ
D.lsof -p 1234
AnswerC

The /proc filesystem exposes process information. /proc/1234/environ contains the environment variables of process 1234 as a null-separated list. Reading this file reveals the exact environment the process was started with, which can help detect injected variables. It is the direct and correct method to inspect a specific process's environment.

Why this answer

To inspect the environment of a running process, the analyst can read /proc/PID/environ. This pseudo-file contains the environment variables as a null-delimited string, reflecting the process's initial environment. Tools like ps and lsof provide other process details but not environment.

The env command only shows the current shell's environment. Thus, accessing /proc/1234/environ is the correct approach.

Exam trap

The trap here is assuming that process listing commands like ps or env can show another process's environment, when only /proc/PID/environ provides that data.

2
MCQmedium

A security analyst is examining a Linux system for signs of compromise. The analyst notices that a suspicious process is running with a parent process ID (PPID) of 1. Which command will display the process tree, showing parent-child relationships, to help identify how the process was launched?

A.pgrep -l suspicious
B.pstree -p
C.top -H
D.ps -ef
AnswerB

The pstree command displays running processes as a tree, visually showing parent-child relationships. The -p option includes PIDs, making it easy to correlate with the suspicious process. This helps the analyst quickly identify the ancestry of the process, such as whether it was spawned by init (PID 1) or another parent, which is crucial for understanding how it was launched.

Why this answer

The pstree -p command provides a visual tree of processes with PIDs, making it straightforward to trace parent-child relationships. This is particularly useful when investigating a suspicious process whose PPID is 1, as it helps determine whether the process was legitimately started by init or if it was orphaned or injected. Other commands lack the hierarchical view needed for this analysis.

Exam trap

The trap here is assuming that ps -ef provides a tree view because it includes PPID, when it actually presents a flat list that requires manual correlation to understand process ancestry.

3
MCQeasy

A Linux administrator needs to identify which processes are currently consuming the most CPU resources. Which command provides an interactive, real-time view of system performance and process activity?

A.ps aux
B.top
C.ls -l /proc
D.df -h
AnswerB

The top command provides an interactive, live dashboard of system activity. It updates at regular intervals, showing the most resource-intensive processes. This allows administrators to sort by CPU usage, identify abnormal spikes, and manage processes, which is essential for diagnosing performance issues or detecting malicious background tasks.

Why this answer

The 'top' command (or its modern alternative 'htop') is the primary utility for real-time monitoring of system resources, including CPU, memory, and running tasks. Understanding how to interpret and interact with these utilities is vital for identifying rogue processes or system bottlenecks that could indicate a malware infection or a resource-exhaustion attack, allowing administrators to terminate suspicious processes immediately using built-in command signals.

Exam trap

Candidates often confuse 'top' with static text-viewing commands like 'cat' or process-listing commands like 'ps', forgetting that 'top' provides the continuous, interactive real-time updates required by the question prompt.

4
MCQmedium

A security analyst needs to determine which network ports are currently listening for incoming connections on a Linux server. Which command is best suited for this task?

A.ss -tulpn
B.ifconfig -a
C.ping -c 5 localhost
D.dig @localhost
AnswerA

The ss command with these flags displays all TCP and UDP listening ports, along with the numeric service port and the process ID (PID) that opened the port. This level of detail is vital for security professionals to map open network sockets back to specific running applications.

Why this answer

Identifying open ports is a critical step in reducing the attack surface of a Linux server. The 'ss' (socket statistics) command is the modern, high-performance replacement for the deprecated 'netstat'. It provides detailed information about active connections, listening ports, and the associated process IDs, helping administrators quickly spot unauthorized services that might serve as entry points for malicious actors.

Exam trap

Candidates often select deprecated commands like 'netstat' or incomplete commands like 'ps', ignoring modern socket statistics utilities like 'ss' that display listening ports efficiently.

5
MCQhard

Refer to the exhibit. A user attempts to delete a file located inside '/opt/backup', but the operation fails with a 'Permission denied' error. Given the directory permissions shown, what is the most likely cause?

A.The user lacks the execute permission on the /opt/backup directory.
B.The user lacks write permission on the /opt/backup directory.
C.The file inside the directory is owned by root and is immutable.
D.The user does not have the 'sudo' command available in their path.
AnswerB

Deleting a file requires the write permission on the parent directory because it involves removing a directory entry. The 'r-x' permissions for others demonstrate that the user does not have write access, which is the mandatory requirement for modifying the contents of a directory, including file deletion.

Why this answer

The directory permissions 'drwxr-xr-x' indicate that the owner (root) has full control, while others have read and execute access. However, because the user is neither root nor the directory owner, they lack write permission (w) on the parent directory. In Linux, deleting a file requires write and execute permissions on the directory containing it, not just the file itself.

This mechanism protects directory integrity from unauthorized modifications by non-privileged users.

Exam trap

Test-takers frequently assume file deletion requires write permissions on the file itself, rather than recognizing that deleting or creating files depends entirely on parent directory permissions.

6
MCQeasy

A junior administrator needs to determine the default gateway configured on a Linux server to troubleshoot outbound connectivity. Which command will display the routing table and show the default route?

A.ip route show
B.netstat -tuln
C.ss -s
D.ifconfig -a
AnswerA

The 'ip route show' command displays the kernel routing table, including the default route typically marked with 'default via'. This directly answers the administrator's need to identify the default gateway. It is the modern replacement for the deprecated 'route' command and works consistently across current Linux distributions.

Why this answer

To view the default gateway, the administrator should inspect the routing table. The 'ip route show' command outputs all routes, including the default route that specifies the gateway via which packets are sent when no other route matches. Interface configuration and socket statistics tools do not expose routing information, so they cannot answer the question.

Exam trap

The trap here is confusing interface configuration tools like ifconfig with routing table tools, even though both relate to networking.

7
MCQhard

A Linux server has the setuid bit set on /usr/bin/passwd. A security engineer notices that a custom binary /opt/tools/backup_tool also has the setuid bit set and is owned by root. The engineer wants to determine whether executing backup_tool will run with root privileges regardless of which user invokes it. Which of the following is the most accurate statement about how the setuid bit affects process credentials on Linux?

A.The process runs with the effective UID of the file owner only if the binary is also executable by the invoking user; otherwise the kernel silently falls back to the invoking user's UID.
B.The setuid bit is ignored on Linux unless the filesystem is mounted with the suid option, so the behavior depends entirely on the mount options of the filesystem holding the binary.
C.The process runs with the effective UID of the file owner, but the real UID remains that of the invoking user, and the saved set-user-ID is set to the file owner's UID.
D.The process runs with the real UID, effective UID, and saved set-user-ID all set to the file owner's UID, so the invoking user's identity is completely lost to the kernel.
AnswerC

When a setuid program is executed, the kernel sets the process's effective UID to the file owner's UID, while the real UID stays as the invoking user's UID. The saved set-user-ID is also set to the file owner's UID, allowing the process to drop and later regain the effective privilege. This is exactly how /usr/bin/passwd can write to /etc/shadow while a normal user runs it.

Why this answer

Executing a setuid binary causes the kernel to set the process's effective UID to the file owner's UID while preserving the real UID of the invoking user. The saved set-user-ID is also set to the file owner's UID, which lets the program temporarily drop and reacquire elevated privileges. This mechanism is why setuid root binaries are high-value targets: any vulnerability in backup_tool could yield root-level access to an unprivileged attacker.

Exam trap

The trap here is believing that setuid changes the real UID as well, when in fact it only changes the effective UID and saved set-user-ID, leaving the real UID intact for accountability.

8
MCQmedium

An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?

A.tail -f /var/log/auth.log
B.head -n 20 /var/log/auth.log
C.less +F /var/log/auth.log
D.cat /var/log/auth.log | grep -v 'accepted'
E.more /var/log/auth.log
AnswerA, C

The '-f' flag tells the tail utility to follow the file, meaning it will continuously display new lines as they are appended to the log. This is the industry-standard method for live log monitoring and immediate detection of authentication failures, such as repeated SSH login attempts or brute-force attacks.

Why this answer

Monitoring logs in real-time is a fundamental skill for GSEC professionals to detect ongoing attacks or system errors. The 'tail -f' command is the standard utility for following a file's growth. Alternatively, 'less +F' offers a more robust interface that allows the admin to toggle between real-time monitoring and static analysis, providing better flexibility when investigating complex log entries during an active incident response scenario.

Exam trap

Candidates often choose static commands like 'cat' or 'more', which do not update in real-time, failing to realize that active incident response requires continuous monitoring of log file growth.

9
MCQeasy

A security administrator is hardening a Linux web server. The administrator needs to ensure that the Apache service, which runs as the user 'www-data', cannot be used to escalate privileges if compromised. Which file should the administrator check to verify that 'www-data' does not have a valid login shell?

A./etc/sudoers
B./etc/group
C./etc/shadow
D./etc/passwd
AnswerD

The /etc/passwd file contains the login shell for each user in its seventh field. By checking this file, the administrator can verify that the 'www-data' account has a non-login shell such as /usr/sbin/nologin or /bin/false, which prevents interactive logins and reduces privilege escalation risk if the service is compromised.

Why this answer

The login shell for a user is stored in the seventh field of /etc/passwd. Service accounts like 'www-data' should have a non-interactive shell such as /usr/sbin/nologin to prevent attackers from obtaining a shell if the service is compromised. Other files contain password hashes, group data, or sudo rules, but none store the login shell assignment.

Exam trap

The trap here is confusing the purpose of /etc/shadow with that of /etc/passwd, assuming that password-related security settings are found in the same file as shell assignments.

10
MCQhard

A security analyst is investigating a suspicious file on a Linux server. The analyst wants to determine the file's inode number, permissions, owner, group, size, and last modification time without modifying the file. Which command should the analyst use?

A.file filename
B.du -h filename
C.ls -l filename
D.stat filename
AnswerD

The stat command displays detailed file metadata including the inode number, permissions, owner, group, size, and timestamps (access, modify, change). It provides all the requested information in a single output and does not modify the file. This makes it the ideal tool for forensic analysis where comprehensive file attributes are needed.

Why this answer

The stat command is designed to display comprehensive file metadata, including the inode number, permissions, ownership, size, and timestamps. Unlike ls, it includes the inode number, which is crucial for forensic analysis. Other commands like file and du provide limited information and do not meet the requirement for a complete metadata overview.

Exam trap

The trap here is assuming that ls -l provides all file metadata, overlooking that it omits the inode number, which is often critical in forensic investigations.

11
Multi-Selectmedium

A security administrator is hardening a Linux server and needs to ensure that user passwords meet complexity requirements and are stored securely. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Disable password aging by setting PASS_MAX_DAYS to 99999.
B.Store passwords in /etc/passwd instead of /etc/shadow to simplify management.
C.Ensure /etc/shadow is readable only by root and the shadow group.
D.Set the password hashing algorithm to SHA-256 in /etc/login.defs.
E.Configure PAM with pam_pwquality to enforce minimum length and character classes.
AnswersC, E

/etc/shadow stores password hashes and must be protected from unauthorized reading. Setting permissions to 640 or 000 with root ownership prevents non-privileged users from accessing hashes, mitigating offline cracking. This is a fundamental security measure for secure password storage. It complements complexity policies by protecting the stored hashes.

Why this answer

To enforce password complexity, the administrator should configure pam_pwquality, which provides configurable checks for length, character classes, and dictionary words. To secure password storage, the administrator must ensure /etc/shadow is properly permissioned so that only root and the shadow group can read it, protecting hashes from unauthorized access. Other options either weaken security or do not address the specific requirements.

Exam trap

The trap here is thinking that password hashing algorithm changes alone enforce complexity, when complexity is actually handled by PAM modules like pam_pwquality.

12
MCQmedium

A security analyst is reviewing a compromised Linux web server. The attacker escalated to root and then ran a script that unlinked the file /var/log/auth.log to hide their tracks. The analyst runs `lsof | grep auth.log` and sees the file is still open by the rsyslogd process, but `ls /var/log/auth.log` reports that the file does not exist. Which of the following best explains why the file content is still accessible through the open file descriptor?

A.The Linux kernel maintains the inode and data blocks until the last open file descriptor referencing the inode is closed, even after the directory entry is removed.
B.The rsyslogd process has the file memory-mapped with mmap, so the page cache keeps a copy that ls can still resolve by inode lookup.
C.The file was moved to a hidden directory by the attacker, and lsof is resolving the path from the process's current working directory rather than the real inode.
D.The ext4 filesystem journals file deletions, and lsof reads the journal to reconstruct the file contents until the journal is overwritten by subsequent writes.
AnswerA

On Linux, unlinking a file only removes the directory entry (the name-to-inode link). The inode's link count drops, but the inode and its data blocks are not reclaimed while any process still holds an open file descriptor. The analyst can recover the content through /proc/<pid>/fd/<n>, which is why the data remains accessible to rsyslogd until it is restarted or closes the descriptor.

Why this answer

When a file is unlinked on Linux, the directory entry is removed but the inode persists as long as a process holds an open file descriptor. rsyslogd keeps auth.log open for writing, so the kernel cannot free the inode or data blocks. The analyst can recover the contents via /proc/<rsyslogd-pid>/fd/<descriptor>, even though the pathname no longer resolves. Restarting rsyslogd would close the descriptor and finally reclaim the inode.

Exam trap

The trap here is assuming that deleting a file immediately frees its disk space and destroys its contents, when in fact an open file descriptor keeps the inode alive until the last handle is closed.

13
MCQmedium

A security administrator needs to ensure that a newly created script, 'cleanup.sh', can only be executed by the file owner, while preventing any other users from reading or writing the file. Which command achieves this configuration?

A.chmod 777 cleanup.sh
B.chmod 755 cleanup.sh
C.chmod 700 cleanup.sh
D.chmod 600 cleanup.sh
AnswerC

The 700 octal mode provides full control to the owner (rwx) and explicitly denies all access to group and other users. This ensures that only the file owner can interact with the script, effectively mitigating risks associated with unauthorized execution or inspection of sensitive administrative tasks on the Linux system.

Why this answer

The chmod command with the octal value 700 applies read, write, and execute permissions exclusively to the owner (7), while setting no permissions for the group (0) and others (0). This follows the principle of least privilege by isolating the script's execution to the authorized user. Restricting access is critical in Linux security to prevent unauthorized execution of potentially sensitive maintenance utilities by standard users or attackers.

Exam trap

Candidates often mix up octal permission positions or confuse read/write/execute values, mistakenly selecting 777 or 007 because they fail to map the owner-only requirement properly.

Ready to test yourself?

Try a timed practice session using only Linux Fundamentals questions.