Courseiva

GSEC Linux Security and Hardening Practice Question

To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?

⚠ Common exam trap

Candidates often select 'Antivirus' or 'Firewall' as security controls for physical boot-level threats, missing the point that these software-based solutions cannot prevent an attacker from booting into a different OS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Setting a BIOS/UEFI password

Boot security is often overlooked but is a critical component of overall system hardening. If an attacker has physical access and the boot process is not secured, they can easily bypass operating system security controls by booting into single-user mode or using a live environment to mount and modify the local filesystem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Setting a BIOS/UEFI password

    Why this is correct

    A BIOS or UEFI password prevents unauthorized users from changing the boot order or modifying hardware-level settings. This is the first line of defense against an attacker trying to boot the system from an external USB drive or optical media to gain access to the underlying data on the disks.

  • ✓

    Configuring a GRUB bootloader password

    Why this is correct

    Password protecting the GRUB bootloader prevents unauthorized users from modifying boot parameters, such as adding 'init=/bin/sh' to gain a root shell. This control ensures that even if someone can see the boot menu, they cannot interfere with the kernel's startup process or enter restricted maintenance modes.

  • ✗

    Enabling the sticky bit on /tmp

    Why it's wrong here

    The sticky bit on the /tmp directory is a filesystem-level security control that prevents users from deleting files owned by others. While it is a necessary hardening step for multi-user environments, it provides no protection against physical access, bootloader manipulation, or unauthorized hardware-level changes during the system startup sequence.

  • ✗

    Disabling the IPv6 network stack

    Why it's wrong here

    Disabling IPv6 is a network hardening step that can reduce the remote attack surface and prevent certain types of tunneling or discovery attacks. However, it does not address physical security concerns or protect the boot process from being hijacked by an attacker who has direct access to the console.

  • ✓

    Implementing Full Disk Encryption (FDE)

    Why this is correct

    Full Disk Encryption ensures that the data remains inaccessible even if the physical hard drive is removed or the system is booted into a different operating system. It requires a passphrase or hardware token to unlock the volume during the early stages of boot, providing robust protection for sensitive data.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.