Which Tool Triggers a Permission Denied Error on /etc/shadow?

A security administrator is performing an audit on a stand-alone UNIX server, and the following message is immediately displayed: (Error 13): /etc/shadow: Permission denied. Which of the following best describes the type of tool that is being used?

  1. Pass-the-hash monitor
  2. File integrity monitor
  3. Forensic analysis
  4. Password cracker Source Reference Answer

Community Votes

D
56%
B
44%

56% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to prioritize concrete technical indicators over contextual job titles, revealing that immediate access failures on hashed password stores point directly to credential-retrieval tools rather than passive monitoring utilities.

This question tests recognition of tool-specific behaviors when accessing highly restricted UNIX files. While many candidates lean toward File Integrity Monitors due to the audit context, community consensus and official guidance confirm that tools actively targeting password hashes are most likely to trigger immediate permission errors on /etc/shadow.

Candidates frequently select File Integrity Monitor (B) because security audits traditionally involve integrity checking; however, they overlook that FIMs are designed to run with appropriate privileges and log changes silently, whereas password crackers actively attempt to extract /etc/shadow hashes and will immediately fail with a permission error if executed without root access.

Community Discussion (20 comments)

Cyberity 👍 9 Selected: D
Password crackers often attempt to access this file to obtain hashed passwords for cracking.
Foreversmall 👍 1 Selected: B
both B and D could theoretically trigger the error, the context of a security audit strongly aligns with File integrity monitor (B). FIM tools are standard components of audits to ensure file integrity, whereas password crackers are more situational and less likely to be the focus of a general audit. The error reflects a permissions issue during routine integrity checks, making B the best answer. Answer: B. File integrity monitor
prabh1251 👍 1 Selected: B
password cracker was running, it would likely try to read or copy the /etc/shadow file, rather than just check permissions.
prabh1251 👍 2 Selected: D
(Permission Denied) happens when you try to access or modify /etc/shadow, which is a highly restricted system file that stores hashed passwords for user accounts.
mejestique 👍 1 Selected: B
B. File integrity monitor Explanation: The "/etc/shadow: Permission denied" error suggests that the tool is trying to access the /etc/shadow file, which stores password hashes on a UNIX system and is highly restricted. A File Integrity Monitor (FIM) checks system files for unauthorized changes, access attempts, or modifications. Since the security administrator is conducting an audit, a FIM tool is likely being used to ensure that critical system files (like /etc/shadow) have not been altered.
dbrowndiver 👍 2 Selected: D
The /etc/shadow file stores encrypted passwords and is protected with strict permissions to prevent unauthorized access. • Scenario Application: The error message (Error 13): /etc/shadow: Permission denied indicates that the tool being used attempted to access the /etc/shadow file but failed due to insufficient permissions. This behavior is consistent with a password cracker attempting to retrieve password hashes for analysis or cracking.
pindinga1 👍 2 Selected: D
The context based, the question says “tool” used for analysis. For my is D pssword cracker.
Eracle 👍 2 Selected: B
Why not D option: a password cracker attempts to crack passwords, not read the file directly. A password cracker typically operates on a copy of the /etc/shadow file (or extracted hashes) and would not generate a “Permission denied” error during its cracking operation.
laternak26 👍 4 Selected: D
D. Password cracker: A password cracker tool is used to attempt to recover passwords from hashed password files. In the case of UNIX-based systems, the /etc/shadow file typically stores user passwords in a hashed format. If a security administrator or attacker is trying to analyze this file, they might encounter the "Permission denied" message if they do not have sufficient privileges to access it. This suggests that the tool being used is likely attempting to crack or analyze the passwords stored in the /etc/shadow file, and it's encountering permission issues. Why not B. File integrity monitor: A file integrity monitor typically checks whether critical system files have been modified. It wouldn't be used to crack passwords or access /etc/shadow in this way, and it wouldn’t typically result in a "Permission denied" error unless there’s an attempt to modify files rather than just monitor them.
AndyK2 👍 4 Selected: B
Strange, Claude says it's FIM. But ChatGPT says Password Cracker. I'd go with FIM - since it makes more sense.
fmeox567 👍 2 Selected: D
D. Password cracker Explanation: The message /etc/shadow: Permission denied indicates that the tool is attempting to access the /etc/shadow file, which typically contains password hashes for user accounts on a UNIX/Linux system. In a normal scenario, this file is restricted to root or privileged users to prevent unauthorized access. This kind of message is commonly seen when a password cracker is trying to access the /etc/shadow file to extract password hashes for the purpose of cracking them (typically using brute force or dictionary attacks). The "Permission denied" error indicates that the tool lacks sufficient privileges to access the file, which is a normal security measure to protect sensitive data.
BevMe 👍 2
B. File Integrity Monitor
cyberWoof 👍 2 Selected: B
File integrity monitor
c7b3ff0 👍 4 Selected: B
I don't know why so many of you think that a security administrator would use a password cracker during an audit, but I bet there are quite a few more reasons they would use a file integrity monitor during an audit. That would probably need to be given permissions to access a restricted file like /etc/shadow before they ran it, and if they didn't give them, I bet it would kick out a don't touch me error just like this. Answer is B.
User92 👍 2 Selected: D
Password crackers often attempt to access the /etc/shadow file to retrieve hashed passwords for cracking.
Ty13 👍 2 Selected: B
B. File Integrity Monitoring The /etc/shadow file stores encrypted user passwords, and you can only access it as root. If you're checking file integrity, you're checking the permissions are still properly set and haven't been changed. You WANT to see 'Permission Denied' if you're auditing the system.
FrozenCarrot 👍 1 Selected: B
The /etc/shadow is a text-based password file.
850bc48 👍 1
D. password cracking
Gman530 👍 2 Selected: B
A file integrity monitor would attempt to read the contents of etc/shadow while doing integrity checks, this may fail due to insufficient permissions. - File Integrity monitor matches the activity of an administrator performing an audit. - Password Cracking is more aligned with pentesting than auditing.
AZZ99 👍 2 Selected: D
Copy pasted to ChatGPT and the answer is D. Make sense to me.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Technical Concept

In UNIX/Linux environments, the /etc/shadow file stores user account password hashes and is strictly protected with restrictive permissions, accessible only by the root user or users in the shadow group. Any non-privileged process attempting to directly read this file will immediately receive a "Permission denied" (Error 13) response.

Why Password Cracker is Correct

Password crackers are designed to extract password hashes from system files for offline brute-force or dictionary attacks. When launched without elevated privileges, these tools automatically scan common credential storage locations like /etc/shadow. The immediate rejection confirms the tool’s active intent to harvest hashes, making D the technically accurate choice. Community comments [1] and [6] correctly highlight that credential-extraction utilities specifically target this file, triggering the error when privilege escalation is missing.

Why Other Options Are Incorrect

  • File Integrity Monitor (B): While audits commonly use FIMs, these tools are built to operate within defined security policies. They either run as root, utilize sudoers configurations, or rely on kernel hooks to monitor changes without generating immediate permission errors during routine checks. As noted in community discussions [2], [5], and [14], the "audit" context is a deliberate distractor; FIMs focus on detecting unauthorized modifications, not harvesting credentials.
  • Pass-the-hash monitor (A): This tracks network authentication traffic using stolen hashes, not local file reads.
  • Forensic analysis (C): Forensic suites acquire disk images or use evidentiary workflows. They do not typically generate runtime permission errors on live systems unless improperly configured, and they are not primarily categorized as "permission-denied-triggering" tools in this context.

Exam Logic & Contextual Traps

CompTIA frequently uses role-based phrasing to misdirect test-takers toward management-oriented answers. However, the objective explicitly asks to identify the tool based on its behavioral output. Immediate failure on a sensitive credential file overrides the administrative context, pointing directly to credential-focused utilities.

Official Reference

  • CompTIA Security+ SY0-701 Objective 1.2 (Technologies and Tools)
  • CompTIA Security+ SY0-701 Objective 1.4 (Security Architecture)
  • CIS Benchmarks for Linux - File Permissions & Shadow Files
  • Linux Foundation Documentation on /etc/shadow permissions

Exam Strategy

When faced with scenario-based questions, prioritize explicit technical symptoms (like specific error messages or file access attempts) over contextual role descriptions. If a tool immediately fails trying to read a sensitive credential store, assume it is a credential-targeting utility rather than a passive monitoring or auditing tool.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide