
GIAC Security Essentials
Domain 4Objective 4
Linux Security and Hardening GSEC Practice Questions (Page 4)
Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
Questions 16–20
- 16
A Linux administrator suspects a rootkit has replaced the 'ps' and 'netstat' binaries. The system is running a distribution that uses RPM packages. Which combination of actions would best confirm the rootkit and identify the original binaries?
Select an answer first - 17
Which kernel parameter is commonly set to restrict the use of kernel pointers in /proc and other interfaces, making it harder for attackers to bypass security mechanisms?
Select an answer first - 18
Which tool is commonly used on Linux to configure netfilter firewall rules?
Select an answer first - 19
A system administrator needs to ensure that a critical configuration file cannot be modified, renamed, or deleted, even by the root user, until a specific maintenance window. Which command should be used to set the appropriate file attribute?
Select an answer first - 20
A security administrator needs to prevent a critical configuration file from being modified, even by the root user, during a security incident. The file is currently owned by root. Which command should the administrator use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.