โ† All Linux Flashcard Decks

Security Flashcards

7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security flashcards as text
  1. Which command forces all users to change their passwords on their next login?

    Answer: chage -d 0 username

    chage -d 0 sets the last password change date to epoch, forcing an immediate password change at next login.

  2. What is the risk of having NOPASSWD in a sudoers entry?

    Answer: The user can run sudo commands without entering a password, bypassing authentication

    NOPASSWD allows a user to invoke sudo without a password, which eliminates a key authentication checkpoint.

  3. Which nmap flag performs a SYN (stealth) scan without completing the TCP handshake?

    Answer: -sS

    nmap -sS sends SYN packets and never completes the handshake, making the scan less likely to appear in connection logs.

  4. What does 'gpg --verify file.sig file' accomplish?

    Answer: Checks that the file's signature matches the signer's public key

    gpg --verify validates the detached signature file against the data file using the signer's public key in your keyring.

  5. Which file defines password complexity and aging policies for PAM-based authentication on RHEL/CentOS?

    Answer: /etc/security/pwquality.conf

    pwquality.conf controls minimum length, character class requirements, and other complexity rules enforced by pam_pwquality.

  6. What is a bind mount in the context of container security?

    Answer: Mounting a host directory into a container, potentially exposing host files

    Bind mounts share a host path inside a container; if sensitive directories like /etc are mounted, they can be read or modified by the container.

  7. Which command installs and activates fail2ban to protect SSH from brute-force attacks?

    Answer: systemctl enable --now fail2ban

    After installing fail2ban, systemctl enable --now fail2ban starts the service immediately and enables it at boot.