
GIAC Security Essentials
Domain 4Objective 4
Linux Security and Hardening GSEC Practice Questions (Page 6)
Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
Questions 26–30
- 26
A system administrator is setting up a shared directory for a project team. The team members need to be able to create and edit files, but they should not be able to delete files created by other team members. The directory is owned by the 'project' group, and all team members are in that group. Which permissions and special bits should be set on the directory?
Select an answer first - 27
A system administrator notices that a legacy daemon is running as root and listening on a network port. The daemon does not need network access and only needs to read a specific configuration file. Which combination of changes would most effectively reduce the risk posed by this daemon?
Select an answer first - 28
A Linux administrator suspects that a running process has been replaced by a rootkit. The process appears in the process list but its executable file on disk has been deleted. Which tool or technique would best help confirm the rootkit and identify the original executable?
Select an answer first - 29
A Linux administrator needs to enforce a password policy that requires passwords to be at least 12 characters long, expire every 90 days, and have a minimum of 5 days between changes. The administrator also wants to lock an account after 5 failed login attempts. Which files should be configured to implement this policy?
Select an answer first - 30
A Linux administrator needs to allow a group of developers to restart the web server and view its logs, but they must not be able to modify the web server configuration or read other sensitive files. The developers are already in the 'devs' group. Which sudoers configuration best enforces least privilege while providing an audit trail?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.