GSEC 401 Questions Part 1. Exam Questions
And Answers (Guaranteed A+)
What is $ - Answer✔Hidden and admin share
What is ./ - Answer✔CLI for beginning to run an executable command in the current directory
What is ./ configure - Answer✔This is the new makefile usually have to type ./configure as most
people don't have the current directory in their search path
What is / - Answer✔Root file system top of the directory hierarchy
What is ./ configure &&make&&make install - Answer✔•make = make would be executed, it
would look for the first target in Makefile and do what the instructions said. The expected end
result would be to build an executable program. •make install = This again invokes make, make
finds the target install in Makefile and files the directions to install the program.
What is /bin - Answer✔location of executable programs, some SUID/SGID
What is /bin, /usr/bin, /usr/local, /opt - Answer✔location of executable programs, some
SUID/SGID
What is /dev or /devices - Answer✔location that contains devices files that programs running on
the system use to communicate with the physical hardware devices controlled by the OS kernel;
directory containing "files" used to talk to system devices
What is /dev/hda - Answer✔HDA is first IDE HDD. SDA1 is 1st partition on that drive. 0-15
What is /dev/sda - Answer✔Sda is the first SCSI HDD. SDA1 is the first partition. 0-15
What is /etc/aliases - Answer✔file is used to contain mail aliases.
What is /etc/default/useradd - Answer✔Config file for password aging
What is /etc/fstab - Answer✔File is used in most Linux/Windows to hold the static name-to-
address maps | Linux = /etc/hosts | Windows = %\systemroot%\system32\drivers\etc\hosts and
lmhosts
What is /etc/hosts - Answer✔File is used in most Linux/Windows to hold the static name-to-
address maps | Linux = /etc/hosts | Windows = %\systemroot%\system32\drivers\etc\hosts and
lmhosts
1|Page
, ©EVERLY 2024/2025 ALL RIGHTS RESERVED.
What is /etc/init.d - Answer✔directory where control scripts are stored; The initialization scripts
used during system startup can also be used to startup services individually. These are located in
the /etc/init.d directories, and can be used to (re)launch services using the following syntax: #
/etc/init.d/<script name> start
What is /etc/inittab - Answer✔Lists each of the init processes the system should start at boot and
stop at shutdown
What is /etc/login.defs - Answer✔Config files for password aging
What is /etc/logrotate.conf - Answer✔moves log files to keep from over filling log space
What is /etc/named.conf - Answer✔(if it exists) is the configuration file for the local name
service cache
What is /etc/pam.d - Answer✔Location of all PAM configuration files
What is /etc/pam.d/system-auth - Answer✔used to enforce passwords strength and reuse
restrictions
What is /etc/passwd - Answer✔Today's Linux environment uses a two file system - /etc/passwd
and /etc/shadow; passwords are not stored in /etc/shadow/; shadow file only accessible by root
What is /etc/resolv.conf - Answer✔tells the host in which order to attempt to resolve names
What is /etc/security/opasswd - Answer✔file created to restrict use of previous passwords
What is /etc/services - Answer✔Mapping of services to port. Works with inetd.conf
What is /etc/shadow - Answer✔Today's Linux environment uses a two file system - /etc/passwd
and /etc/shadow; passwords are not stored in /etc/shadow/; shadow file only accessible by root
What is /etc/xinetd.conf - Answer✔Global xinetd configuratio file. Read-only once the xinet
service is started.
What is /export/home, /home - Answer✔user home directories.
What is /home - Answer✔user home directories
What is /opt - Answer✔executable programs, some SUID/SGID
What is /sbin - Answer✔Contains system binary files
What is /usr - Answer✔Most of the critical components of the OS live, including system
binaries, programming libraries and tools, and on-line documentation; Ready-Only unless OS is
upgraded or patches installed. Files should be protected.
What is /usr/bin - Answer✔executable programs, some SUID/SGID
What is /usr/local - Answer✔executable programs, some SUID/SGID
What is /usr/sbin - Answer✔Contains system binary files.
2|Page
, ©EVERLY 2024/2025 ALL RIGHTS RESERVED.
What is /var - Answer✔Systems keeps frequent changing data, such as log files and temp queues
for system services like email
What is /var/log/secure - Answer✔Activities related to the use of the su command are
authentication types of activities, where the user must authenticate themselves to the system
before being allowed to switch users. Authentication activities are logged under the rules
associated with the "auth" and "authpriv" facilities in the syslog.conf file. Based on this
syslog.conf file, the "authpriv" facility messages are supposed to be sent to /var/log/secure.
What is | - Answer✔Piping use; Piping command output into another command as input.
What is > - Answer✔Creating output files
What is3 roles of SSL - Answer✔•Encryption, •Server ID Verification, •Data Integrity; (SSL
uses port 443)
What is 3DES - Answer✔used to overcome the weakness of short key length of DES and meet in
the middle attack of double DES; executes 48 rounds 168 bit key length (168 bit - 3 keys)
What is 5 Vulnerability Axioms(General Truths) - Answer✔•1.) Vulnerabilities are the gateways
through which threats are manifested. •2.) Scans without remediation have little value. •3.) Little
scanning and remediation is better than a lot scanning and no remediation. •4.) Prioritizing is
critical. •5.) Stay on track.
What is 6 Step Process for Incident Handling - Answer✔•1.) Preparation •2.) Identification •3.)
Containment •4.) Eradication •5.) Recovery •6.) Lessons Learned
What is 802.1x - Answer✔A method for controlling access to your network to only authenticated
devices or users; Used with VLANs. 802.1x = authentication; provides network-level
authentication
What is Absinthe - Answer✔Tool that can be used effectively for blind SQL injection
What is Absolute File Modes - Answer✔Linux file permissions written in number format instead
of rwx format; rwx|rwx|rwx; (r=4, w=2, x=1) 111|111|111 =777
What is Acceptable Risk - Answer✔method of mitigating this is with awareness method of
mitigating this is with awareness •Who decides what the organization can afford to risk
What is Access Control - Answer✔Typical users follow the past you anticipated through the site.
Attackers poke, prod, and guess their way into every nook and crann. Keep users out of parts of
the server you don't intend them to be in ex. default pages, sample sites; unnecessary
programming languages; code library pages and configuration files; disable directory browsing;
URL directory traversal
What is Access Control - DAC - Answer✔Access managed by users. (Used by most Linux
Variants "book 6, pg 211"); Consists of something a user can manage(ex. Username and
password); least restrictive
3|Page
, ©EVERLY 2024/2025 ALL RIGHTS RESERVED.
What is Access Control - List Based - Answer✔list of users and their privileges with each object;
Associates a list of users and their privileges with each object; each object has a default set of
privileges that applies to unlisted users
What is Access Control - MAC - Answer✔Controls are set by the system and cannot be
overwritten by administrator; Lot of work to maintain because all data has classification and all
users have clearance (SELinux)
What is Access Control - RBAC - Answer✔Access based on rules for a specific object; Target
actions based on rules for subjects(entities) operating on objects (data/other resources);
implemented in a variety of software programs and OS's (ex. Firewalls)
What is Access Control - Token Based - Answer✔Associate a list of objects and their privileges
(called capabilities) with each user; opposite of List-based
What is Access Control Techniques - Answer✔Discretionary (DAC), Mandatory (MAC), Role-
based (RBAC), Ruleset-based (RSBAC), List-based, Token-based
What is access management - Answer✔4 tasks: account administration, maintenance,
monitoring, and revocation
What is Accountability - Answer✔Ensures individuals are held accountable for their actions and
you can trace back what occurred on a system through detailed auditing; Deals with knowing
who did what and when
What is ACE - Answer✔Individual permissions in the Discretionary Access Control List
(DACL).
What is Achilles - Answer✔A powerful but basic tool for identifying vulnerabilities in Web
applications. HTTP Proxy
What is ACK - Answer✔used to acknowledge the receipt of data
What is acldiag.exe - Answer✔displays permissions on Active Directory objects and can be used
to calculate effective permissions.
What is Acronis - Answer✔Binary Disk Imager
What is Actions (syslog.conf) - Answer✔Specify how specific messages should be handled by
syslog
What is Active Directory - Answer✔With AD you can make a change to the AD database on any
domain controller in an AD domain, and this change will then be replicated to all other domain
controllers automatically. With Windows 2008, Microsoft introduced an important exception to
multi-master replication when a domain controller is running Windows Server 2008 or later and
the administrator has decided to install that controller as a read-only domain controller (RODC).
What is Active Directory Domain - Answer✔active directory is the name of the shared database
that is installed on all windows servers when it is promoted to a domain controller; Central
management for SIDs and SATs
4|Page