Courseiva

GSEC · topic practice

Linux Security and Hardening practice questions

This domain covers hardening Linux hosts on the GSEC exam: controlling physical and boot access, configuring auditd file watches, writing nftables rules that default-deny, and enforcing password quality with PAM. Questions are scenario-based, asking you to pick the correct commands, config files, or control combinations rather than recall definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Linux Security and Hardening

What the exam tests

What to know about Linux Security and Hardening

Be able to harden a Linux host end to end: lock down boot and physical access, add auditd watches, build least-privilege nftables rules, and configure PAM pwquality. The single most important thing is knowing which file or command actually enforces each control.

Boot-loader and BIOS/UEFI passwords plus GRUB restrictions to stop unauthorized physical or single-user boot access

auditd watch rules on /etc/passwd and /etc/group, and how audit records are written and queried with ausearch

nftables default-drop input chains that permit only established traffic and SSH on port 22

PAM pwquality settings in /etc/security/pwquality.conf enforcing length, character class, and complexity requirements

Watch out for

Common Linux Security and Hardening exam traps

  • ▸Assuming file permissions alone stop boot tampering; physical access controls like BIOS/UEFI and GRUB passwords are also required.
  • ▸Writing nftables rules that accept SSH but forget the default drop policy, leaving all other inbound ports open.
  • ▸Setting password length in login.defs or PAM but not enabling the pwquality module, so the policy is never enforced.

Practice set

Linux Security and Hardening questions

20 questions · select your answer, then reveal the explanation

A security engineer needs to manage Mandatory Access Control (MAC) settings on a Red Hat Enterprise Linux (RHEL) system. Which TWO commands are most essential for viewing and modifying the state and file labeling of SELinux?

Refer to the exhibit. An analyst is reviewing the /etc/shadow file to verify account security policies. Based on the entry for the user 'jdoe', what is the current password expiration policy?

Exhibit

jdoe:$6$rounds=5000$saltstring$8hG...:19000:0:90:7:::

A system administrator wants to review recent authentication failures on a modern Linux distribution that uses systemd. Which command is the most efficient way to view these logs in real-time?

Refer to the exhibit. What is the effect of this entry in the /etc/sudoers file for a user who belongs to the 'webadmins' group?

Exhibit

%webadmins ALL=(root) /usr/bin/apt-get update, /usr/bin/apt-get upgrade

A security engineer is hardening an Ubuntu 22.04 web server that hosts a public Apache site. The site's document root is /var/www/html, owned by root:root with mode 755. Developers need to upload files without SSH access, so the engineer wants to ensure that any file or directory created inside /var/www/html by the apache user cannot be executed as a program, while still allowing PHP files to be served by the web server. Which control best accomplishes this?

A security administrator is configuring SSH access on a Debian 12 bastion host used by contractors. Contractors must authenticate with SSH keys, but the administrator wants to ensure that contractor keys cannot be used to open additional channels such as port forwarding or agent forwarding into the internal network, even if a contractor adds directives to their own client configuration. Which sshd_config approach enforces this server-side?

A security analyst is reviewing a Linux server's auditd configuration. The goal is to monitor all attempts to modify the /etc/passwd file, including successful and failed write attempts. Which audit rule correctly achieves this?

A security administrator is hardening a Linux server that uses systemd. The administrator wants to restrict the ability of users to escalate privileges via the su command. Which TWO actions should the administrator take? (Choose two.)

A system administrator needs to harden a public-facing Linux server against automated brute-force attacks. Which configuration change in the /etc/ssh/sshd_config file provides the most significant reduction in the attack surface regarding credential stuffing?

An information security auditor discovers a custom compiled binary in a shared directory with the following permissions: -rwsr-xr-x. The file is owned by the root user. What is the primary security implication of this finding?

To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?

A security administrator needs to block all incoming traffic to a server except for SSH (port 22) using the nftables framework. Which configuration approach best follows the principle of least privilege?

A security engineer is configuring a Linux server to enforce password quality for all local accounts. The requirement is that passwords must be at least 14 characters long, contain at least one uppercase letter, one lowercase letter, one digit, and one special character, and must not repeat any of the last 5 passwords. Which file should the engineer edit to enforce these settings?

A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?

A junior administrator is preparing a new Ubuntu server for production. The security policy states that the root account must not be usable for direct interactive logon, and that administrative tasks must be performed through a named account with elevated privileges. Which configuration change best enforces this policy?

A security engineer is reviewing a production RHEL 9 server and finds that several users have entries in /etc/sudoers granting them NOPASSWD for specific commands. The engineer wants to verify which users can run commands as root without a password and also check for any syntax errors in the sudoers configuration. Which approach provides the most reliable verification?

A security analyst is hardening a fleet of Linux servers and wants to reduce the risk of privilege escalation through file capabilities and setuid binaries. The analyst plans to audit and restrict these mechanisms. Which two actions best support this goal? (Choose two.)

A security administrator is configuring auditd on a Linux server to meet a compliance requirement that all changes to user and group files be logged. The administrator adds a watch on /etc/passwd and /etc/group. After applying the rules, the administrator notices that modifications made using the 'vipw' and 'vigr' commands are not generating audit events, even though direct edits with a text editor are logged. Which explanation best describes why this occurs?

A system administrator is hardening a Linux server and wants to ensure that users cannot log in with empty passwords. Which command should the administrator use to check for accounts with empty password fields in /etc/shadow?

A security engineer is implementing file integrity monitoring on a Linux server. The engineer wants to use AIDE to detect unauthorized changes to critical system files. After initializing the AIDE database, which command should be used to perform a manual check and compare the current file system state against the baseline?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Linux Security and Hardening sessions

Start a Linux Security and Hardening only practice session

Every question in these sessions is drawn from the Linux Security and Hardening domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Linux Security and Hardening?
Be able to harden a Linux host end to end: lock down boot and physical access, add auditd watches, build least-privilege nftables rules, and configure PAM pwquality. The single most important thing is knowing which file or command actually enforces each control.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Linux Security and Hardening questions in a focused session?
Yes — the session launcher on this page draws every question from the Linux Security and Hardening domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.