Courseiva

GSEC · domain

Linux Security and Hardening

This domain covers hardening Linux hosts on the GSEC exam: controlling physical and boot access, configuring auditd file watches, writing nftables rules that default-deny, and enforcing password quality with PAM. Questions are scenario-based, asking you to pick the correct commands, config files, or control combinations rather than recall definitions.

13 questions2 easy7 medium4 hard

Focused practice

Practice Linux Security and Hardening questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Linux Security and Hardening

Be able to harden a Linux host end to end: lock down boot and physical access, add auditd watches, build least-privilege nftables rules, and configure PAM pwquality. The single most important thing is knowing which file or command actually enforces each control.

Boot-loader and BIOS/UEFI passwords plus GRUB restrictions to stop unauthorized physical or single-user boot access

auditd watch rules on /etc/passwd and /etc/group, and how audit records are written and queried with ausearch

nftables default-drop input chains that permit only established traffic and SSH on port 22

PAM pwquality settings in /etc/security/pwquality.conf enforcing length, character class, and complexity requirements

Watch out for

Common Linux Security and Hardening exam traps

  • ▸Assuming file permissions alone stop boot tampering; physical access controls like BIOS/UEFI and GRUB passwords are also required.
  • ▸Writing nftables rules that accept SSH but forget the default drop policy, leaving all other inbound ports open.
  • ▸Setting password length in login.defs or PAM but not enabling the pwquality module, so the policy is never enforced.

Question index

All Linux Security and Hardening questions (13)

Click any question to see the full explanation, or start a practice session above.

1

A system administrator needs to harden a public-facing Linux server against automated brute-force attacks. Which configuration change in the /etc/ssh/sshd_config file provides the most significant reduction in the attack surface regarding credential stuffing?

Medium
2

A security analyst is hardening a fleet of Linux servers and wants to reduce the risk of privilege escalation through file capabilities and setuid binaries. The analyst plans to audit and restrict these mechanisms. Which two actions best support this goal? (Choose two.)

Medium
3

A security administrator is configuring auditd on a Linux server to meet a compliance requirement that all changes to user and group files be logged. The administrator adds a watch on /etc/passwd and /etc/group. After applying the rules, the administrator notices that modifications made using the 'vipw' and 'vigr' commands are not generating audit events, even though direct edits with a text editor are logged. Which explanation best describes why this occurs?

Medium
4

A system administrator is hardening a Linux server and wants to ensure that users cannot log in with empty passwords. Which command should the administrator use to check for accounts with empty password fields in /etc/shadow?

Easy
5

A security administrator is hardening the boot process of a production Ubuntu 22.04 server that uses GRUB 2. The policy requires that any interactive modification to the kernel command line at the GRUB menu must be blocked, and that the bootloader configuration file must be unreadable by unprivileged users. Which action should the administrator take to meet these requirements?

Medium
6

A security engineer is configuring a Linux server to enforce password quality for all local accounts. The requirement is that passwords must be at least 14 characters long, contain at least one uppercase letter, one lowercase letter, one digit, and one special character, and must not repeat any of the last 5 passwords. Which file should the engineer edit to enforce these settings?

Medium
7

A junior administrator is preparing a new Ubuntu server for production. The security policy states that the root account must not be usable for direct interactive logon, and that administrative tasks must be performed through a named account with elevated privileges. Which configuration change best enforces this policy?

Easy
8

An information security auditor discovers a custom compiled binary in a shared directory with the following permissions: -rwsr-xr-x. The file is owned by the root user. What is the primary security implication of this finding?

Hard
9

A security engineer is implementing file integrity monitoring on a Linux server. The engineer wants to use AIDE to detect unauthorized changes to critical system files. After initializing the AIDE database, which command should be used to perform a manual check and compare the current file system state against the baseline?

Hard
10

To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?

Hard
11

A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?

Medium
12

A security engineer is reviewing a production RHEL 9 server and finds that several users have entries in /etc/sudoers granting them NOPASSWD for specific commands. The engineer wants to verify which users can run commands as root without a password and also check for any syntax errors in the sudoers configuration. Which approach provides the most reliable verification?

Hard
13

A security administrator needs to block all incoming traffic to a server except for SSH (port 22) using the nftables framework. Which configuration approach best follows the principle of least privilege?

Medium

Frequently asked questions

What does the Linux Security and Hardening domain cover on the GSEC exam?
Be able to harden a Linux host end to end: lock down boot and physical access, add auditd watches, build least-privilege nftables rules, and configure PAM pwquality. The single most important thing is knowing which file or command actually enforces each control.
How many questions are in this domain?
This page lists all 13 Linux Security and Hardening questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Linux Security and Hardening questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC linux security and hardening Practice Questions