Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security flashcards as text
Which command forces all users to change their passwords on their next login?
Answer: chage -d 0 username
chage -d 0 sets the last password change date to epoch, forcing an immediate password change at next login.
What is the risk of having NOPASSWD in a sudoers entry?
Answer: The user can run sudo commands without entering a password, bypassing authentication
NOPASSWD allows a user to invoke sudo without a password, which eliminates a key authentication checkpoint.
Which nmap flag performs a SYN (stealth) scan without completing the TCP handshake?
Answer: -sS
nmap -sS sends SYN packets and never completes the handshake, making the scan less likely to appear in connection logs.
What does 'gpg --verify file.sig file' accomplish?
Answer: Checks that the file's signature matches the signer's public key
gpg --verify validates the detached signature file against the data file using the signer's public key in your keyring.
Which file defines password complexity and aging policies for PAM-based authentication on RHEL/CentOS?
Answer: /etc/security/pwquality.conf
pwquality.conf controls minimum length, character class requirements, and other complexity rules enforced by pam_pwquality.
What is a bind mount in the context of container security?
Answer: Mounting a host directory into a container, potentially exposing host files
Bind mounts share a host path inside a container; if sensitive directories like /etc are mounted, they can be read or modified by the container.
Which command installs and activates fail2ban to protect SSH from brute-force attacks?
Answer: systemctl enable --now fail2ban
After installing fail2ban, systemctl enable --now fail2ban starts the service immediately and enables it at boot.