Which Tool Triggers a Permission Denied Error on /etc/shadow?
A security administrator is performing an audit on a stand-alone UNIX server, and the following message is immediately displayed: (Error 13): /etc/shadow: Permission denied. Which of the following best describes the type of tool that is being used?
Community Votes
56% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to prioritize concrete technical indicators over contextual job titles, revealing that immediate access failures on hashed password stores point directly to credential-retrieval tools rather than passive monitoring utilities.
This question tests recognition of tool-specific behaviors when accessing highly restricted UNIX files. While many candidates lean toward File Integrity Monitors due to the audit context, community consensus and official guidance confirm that tools actively targeting password hashes are most likely to trigger immediate permission errors on /etc/shadow.
Candidates frequently select File Integrity Monitor (B) because security audits traditionally involve integrity checking; however, they overlook that FIMs are designed to run with appropriate privileges and log changes silently, whereas password crackers actively attempt to extract /etc/shadow hashes and will immediately fail with a permission error if executed without root access.
Community Discussion (20 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Technical Concept
In UNIX/Linux environments, the/etc/shadow file stores user account password hashes and is strictly protected with restrictive permissions, accessible only by the root user or users in the shadow group. Any non-privileged process attempting to directly read this file will immediately receive a "Permission denied" (Error 13) response.Why Password Cracker is Correct
Password crackers are designed to extract password hashes from system files for offline brute-force or dictionary attacks. When launched without elevated privileges, these tools automatically scan common credential storage locations like/etc/shadow. The immediate rejection confirms the tool’s active intent to harvest hashes, making D the technically accurate choice. Community comments [1] and [6] correctly highlight that credential-extraction utilities specifically target this file, triggering the error when privilege escalation is missing.Why Other Options Are Incorrect
- File Integrity Monitor (B): While audits commonly use FIMs, these tools are built to operate within defined security policies. They either run as root, utilize sudoers configurations, or rely on kernel hooks to monitor changes without generating immediate permission errors during routine checks. As noted in community discussions [2], [5], and [14], the "audit" context is a deliberate distractor; FIMs focus on detecting unauthorized modifications, not harvesting credentials.
- Pass-the-hash monitor (A): This tracks network authentication traffic using stolen hashes, not local file reads.
- Forensic analysis (C): Forensic suites acquire disk images or use evidentiary workflows. They do not typically generate runtime permission errors on live systems unless improperly configured, and they are not primarily categorized as "permission-denied-triggering" tools in this context.
Exam Logic & Contextual Traps
CompTIA frequently uses role-based phrasing to misdirect test-takers toward management-oriented answers. However, the objective explicitly asks to identify the tool based on its behavioral output. Immediate failure on a sensitive credential file overrides the administrative context, pointing directly to credential-focused utilities.Official Reference
- CompTIA Security+ SY0-701 Objective 1.2 (Technologies and Tools)
- CompTIA Security+ SY0-701 Objective 1.4 (Security Architecture)
- CIS Benchmarks for Linux - File Permissions & Shadow Files
- Linux Foundation Documentation on /etc/shadow permissions
Exam Strategy
When faced with scenario-based questions, prioritize explicit technical symptoms (like specific error messages or file access attempts) over contextual role descriptions. If a tool immediately fails trying to read a sensitive credential store, assume it is a credential-targeting utility rather than a passive monitoring or auditing tool.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →