Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security flashcards as text
What is the primary purpose of the Linux Audit daemon (auditd)?
Answer: Record security-relevant system events to a tamper-evident log
auditd logs security events like file access, syscalls, and authentication attempts to /var/log/audit/audit.log.
Which iptables chain is used to filter packets destined for the local system?
Answer: INPUT
The INPUT chain processes packets whose destination is the local host.
What does 'find / -perm -4000' search for?
Answer: Files with the SUID bit set
-perm -4000 matches files where the SUID bit (4000) is set, which can be a privilege escalation risk.
Which OpenSSL command generates a 2048-bit RSA private key?
Answer: openssl genrsa -out key.pem 2048
openssl genrsa -out key.pem 2048 generates a 2048-bit RSA private key and writes it to key.pem.
What security risk is introduced by having a world-writable /tmp directory without the sticky bit?
Answer: Any user can delete or overwrite other users' files
Without the sticky bit, any user with write access to /tmp can delete files owned by other users, enabling attacks like symlink races.
Which command displays the SELinux security context of a file?
Answer: ls -Z filename
ls -Z shows the SELinux security context (user:role:type:level) alongside standard file metadata.
What is the function of the /etc/hosts.deny file in TCP Wrappers?
Answer: Specifies hosts denied access to wrapped network services
TCP Wrappers checks /etc/hosts.allow first; if no match, /etc/hosts.deny is checked to block access to wrapped services.