Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security flashcards as text
Which command shows all open network ports and the processes listening on them?
Answer: ss -tlnp
ss -tlnp shows TCP listening ports (-t -l), numeric addresses (-n), and the owning process (-p).
What is the correct permission octal value for a file readable and writable by owner only?
Answer: 600
600 grants read (4) and write (2) to the owner only; group and others have no permissions.
Which AppArmor command places a profile into enforce mode?
Answer: aa-enforce /etc/apparmor.d/profile
aa-enforce activates an AppArmor profile in enforce mode, blocking policy violations.
What does the 'umask 027' command do?
Answer: New files get permissions 640 and new directories get 750
umask 027 masks out write for group and all permissions for others, resulting in 640 for files and 750 for directories.
Which log file records failed and successful sudo usage on most Linux distributions?
Answer: /var/log/auth.log or /var/log/secure
Authentication events including sudo use are written to /var/log/auth.log (Debian-based) or /var/log/secure (RHEL-based).
What is the effect of running 'passwd -l username' on a Linux system?
Answer: Locks the user account by prefixing a '!' to the password hash
passwd -l locks an account by prepending '!' to the hashed password in /etc/shadow, preventing password-based login.
Which command checks the integrity of installed RPM packages against their checksums?
Answer: rpm -Va
rpm -Va verifies all installed packages, reporting any files that differ from the original package metadata.