โ† All Linux Flashcard Decks

Security Flashcards

7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security flashcards as text
  1. Which command displays the current SELinux enforcement mode?

    Answer: getenforce

    getenforce prints the current SELinux mode: Enforcing, Permissive, or Disabled.

  2. What does the sticky bit do when set on a directory?

    Answer: Only the file owner or root can delete files within it

    The sticky bit on a directory prevents users from deleting or renaming files they do not own, even if they have write permission on the directory.

  3. Which firewalld command adds a service permanently to the public zone?

    Answer: firewall-cmd --zone=public --add-service=http --permanent

    The --permanent flag makes the rule persist across reboots; without it the change is runtime-only.

  4. What is the purpose of the /etc/sudoers file?

    Answer: Define which users can run commands as root or another user

    /etc/sudoers specifies user and group privileges for running commands via sudo.

  5. Which SSH configuration option disables password-based login, allowing only key-based authentication?

    Answer: PasswordAuthentication no

    Setting PasswordAuthentication no in /etc/ssh/sshd_config forces clients to use key-based authentication.

  6. What does 'chattr +i /etc/passwd' accomplish?

    Answer: Makes the file immutable so no user, including root, can modify or delete it

    The +i attribute makes a file immutable; even root cannot alter it until the attribute is removed with chattr -i.

  7. Which tool is used to audit Linux system calls made by a process for security analysis?

    Answer: strace

    strace intercepts and records system calls made by a process, useful for identifying suspicious behavior.

Security Flashcards โ€” Linux Study Cards with Answers