A security administrator is performing an audit on a stand-alone UNIX server, and the following message is immediately displayed: (Error 13): /etc/shadow: Permission denied. Which of the following best describes the type of tool that is being used?
Choose an answer
Tap an option to check your answer.
Correct answer: Password cracker.
Why this is the answer
The error message "(Error 13): /etc/shadow: Permission denied" indicates an attempt to access the /etc/shadow file, which stores encrypted password hashes on UNIX-like systems. This file is highly protected, and unauthorized access is typically denied. A password cracker is a tool designed to gain access to or recover passwords, often by attempting to read and decrypt hash files like /etc/shadow. The "Permission denied" error directly results from such an attempt without proper privileges. A pass-the-hash monitor observes network traffic for hash-based authentication attempts, not direct file access. A file integrity monitor tracks changes to files and directories, not attempts to access protected password files. Forensic analysis is a broad discipline for investigating digital evidence, but the specific error points to a tool attempting to crack passwords.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed