HomeSubjectsUniversityBlogAbout

OS Security

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Operating system security covers the mechanisms an OS uses to protect processes, files and memory, and the hardening steps that shrink its attack surface. Linux questions test file permissions, chmod notation, the SUID and SGID bits, sudo, and mandatory access control through SELinux or AppArmor, with IMA for integrity measurement. Windows items cover User Account Control, audit policies, Group Policy and access control lists. Memory protections such as ASLR and DEP/NX are asked in relation to buffer overflow attacks, as are privilege escalation, rootkits and secure boot. Patch management, disabling unused services and container isolation, including container escape risks, complete the topic.

Below are 30 practice questions from a pool of 210 OS Security MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

OS SecurityEasy

Q1. What is OS hardening?

  1. A.Making the OS run faster within enterprise security environments
  2. B.Increasing storage capacity within enterprise security environments
  3. C.Installing new applications within enterprise security environments
  4. D.The process of securing an operating system by reducing its attack surface✓ Correct

Explanation

OS hardening involves configuring and securing an operating system by removing unnecessary services and applying patches.

Report an error in this question

OS SecurityEasy

Q2. What is a user account in operating system security?

  1. A.A software application used for enterprise computing operations
  2. B.A network connection used in enterprise network infrastructure
  3. C.An identity used to access and interact with the OS with specific permissions✓ Correct
  4. D.A social media profile within modern computing environments

Explanation

A user account provides an identity with defined permissions and privileges for OS access.

Report an error in this question

OS SecurityEasy

Q3. Why is it important to keep operating systems updated?

  1. A.To fix security vulnerabilities and improve system stability✓ Correct
  2. B.To make the computer slower within enterprise computing infrastructure
  3. C.To increase file storage within the data management framework
  4. D.To change the wallpaper within enterprise computing infrastructure

Explanation

OS updates patch known security vulnerabilities, fix bugs, and improve system stability.

Report an error in this question

OS SecurityEasy

Q4. What is a security patch?

  1. A.A software update that fixes a specific security vulnerability✓ Correct
  2. B.A decorative element within modern computing environments
  3. C.A physical patch on hardware installed within computing infrastructure
  4. D.A category of self-replicating malicious software

Explanation

A security patch is a targeted software update designed to fix a specific security vulnerability.

Report an error in this question

OS SecurityEasy

Q5. What is a system log?

  1. A.A file that records events, errors, and activities within the operating system✓ Correct
  2. B.A strain of self-replicating malicious software programs
  3. C.A physical network cable used for connecting infrastructure devices
  4. D.A physical security measure for protecting building infrastructure

Explanation

System logs record events, errors, warnings, and activities within the OS for troubleshooting and auditing.

Report an error in this question

OS SecurityEasy

Q6. What is the purpose of disabling unnecessary services on an OS?

  1. A.To free up disk space only within enterprise computing infrastructure
  2. B.To reduce the attack surface by eliminating potential entry points✓ Correct
  3. C.To make the OS look cleaner within enterprise computing infrastructure
  4. D.To speed up boot time only for improved operational efficiency

Explanation

Disabling unnecessary services reduces the attack surface by removing potential entry points.

Report an error in this question

OS SecurityEasy

Q7. What is the purpose of file permissions in an OS?

  1. A.To compress files for reducing disk storage consumption
  2. B.To encrypt all files automatically
  3. C.To make files larger within the data management framework
  4. D.To control who can read, write, or execute files✓ Correct

Explanation

File permissions control access to files and directories by specifying what actions different users can perform.

Report an error in this question

OS SecurityMedium

Q8. What is a chroot jail in Linux security?

  1. A.An operation that changes the root directory for a process, isolating it from the rest of the file system✓ Correct
  2. B.A physical jail or correctional facility structure within modern computing environments
  3. C.A network configuration for firewall rule settings deployed across enterprise environments
  4. D.A specific type of user account with limited access within the identity management system

Explanation

A chroot jail isolates a process by changing its apparent root directory, limiting its file system access.

Report an error in this question

OS SecurityEasy

Q9. What is Windows Defender?

  1. A.A built-in antimalware component of Windows operating system✓ Correct
  2. B.A file manager for organizing system directories
  3. C.A standard web browser for accessing internet sites
  4. D.A first-person video game for entertainment

Explanation

Windows Defender is the built-in antivirus and antimalware software included with Windows.

Report an error in this question

OS SecurityEasy

Q10. What is the root account in Linux?

  1. A.The superuser account with unrestricted access to all commands and files✓ Correct
  2. B.A regular user account within the identity management system
  3. C.A temporary account within the identity management system
  4. D.A guest account within the identity management system

Explanation

The root account in Linux is the superuser with the highest level of access.

Report an error in this question

OS SecurityMedium

Q11. What is mandatory access control (MAC) in operating systems?

  1. A.The OS enforces access rules based on security labels that users cannot override✓ Correct
  2. B.Users set their own permissions within enterprise security environments
  3. C.All users have equal access with no meaningful distinction between them
  4. D.No access control is needed in any deployment scenario or context

Explanation

MAC enforces access controls based on security labels which regular users cannot modify.

Report an error in this question

OS SecurityMedium

Q12. What is the purpose of SELinux?

  1. A.To provide mandatory access control security policies in Linux✓ Correct
  2. B.To install and manage software packages efficiently
  3. C.To optimize and speed up the Linux kernel performance
  4. D.To create and manage virtual machine environments

Explanation

SELinux implements mandatory access control policies that restrict actions processes and users can perform.

Report an error in this question

OS SecurityMedium

Q13. What is Address Space Layout Randomization (ASLR)?

  1. A.A standard network communication protocol for data transmission
  2. B.A file management technique for organizing directories used in enterprise computing environments
  3. C.A symmetric key data encryption algorithm applied to data protection workflows
  4. D.A security technique that randomly arranges memory address space of processes to prevent exploitation✓ Correct

Explanation

ASLR randomly arranges key data areas in a process's address space, making it harder for attackers to predict memory locations.

Report an error in this question

OS SecurityMedium

Q14. What is the Windows Registry and why is it important for security?

  1. A.An automated backup solution for enterprise data recovery needs
  2. B.A user account type with specifically assigned access permissions
  3. C.A hierarchical database storing OS and application settings that if compromised can affect system security✓ Correct
  4. D.A next-generation firewall security appliance deployed across enterprise environments

Explanation

The Windows Registry stores critical configuration settings. Malicious modifications can disable security features.

Report an error in this question

OS SecurityEasy

Q15. Which is a basic OS security practice?

  1. A.Disabling the firewall within enterprise security environments
  2. B.Running all programs as administrator
  3. C.Using strong passwords and enabling automatic updates✓ Correct
  4. D.Sharing admin passwords within enterprise security environments

Explanation

Using strong passwords and enabling automatic updates are fundamental OS security practices.

Report an error in this question

OS SecurityMedium

Q16. What is Data Execution Prevention (DEP)?

  1. A.An automated feature for scheduling data backups for managing enterprise data resources
  2. B.A security feature that marks memory regions as non-executable to prevent code execution from those areas✓ Correct
  3. C.A built-in file encryption tool for data protection applied to data protection workflows
  4. D.A network traffic monitoring feature for analysis used in enterprise network infrastructure

Explanation

DEP prevents code from being run in memory regions marked as non-executable, protecting against buffer overflow attacks.

Report an error in this question

OS SecurityMedium

Q17. What is the purpose of Windows Group Policy?

  1. A.To centrally manage and configure OS settings, user permissions, and security policies✓ Correct
  2. B.To create social media groups for enterprise communication
  3. C.To logically group related files within directories and management
  4. D.To organize and arrange desktop icons into folders and management

Explanation

Windows Group Policy enables administrators to centrally manage security settings and access controls.

Report an error in this question

OS SecurityMedium

Q18. What is process isolation in operating systems?

  1. A.Keeping each process's memory space separate to prevent unauthorized access between processes✓ Correct
  2. B.A specific type of preemptive multitasking method used in enterprise computing environments
  3. C.Running all system processes in shared memory space across computing environments
  4. D.Immediately stopping and terminating all processes across computing environments

Explanation

Process isolation ensures each process runs in its own memory space, preventing unauthorized cross-process access.

Report an error in this question

OS SecurityHard

Q19. What is the purpose of Control Flow Integrity (CFI)?

  1. A.To ensure program execution follows the intended control flow graph, preventing code-reuse attacks✓ Correct
  2. B.To manage file systems within the data management framework and management
  3. C.To control user access within enterprise computing infrastructure and management
  4. D.To control traffic flow on networks across the enterprise network infrastructure

Explanation

CFI verifies that program control flow follows a predetermined graph, preventing attacks like Return-Oriented Programming.

Report an error in this question

OS SecurityHard

Q20. What is integrity measurement architecture (IMA) in Linux?

  1. A.Detecting unauthorized file changes by maintaining and verifying cryptographic hashes✓ Correct
  2. B.Measuring and reporting available disk storage capacity on server devices
  3. C.Improving overall system performance throughput and resource utilization
  4. D.Compressing files to reduce disk storage consumption across system drives

Explanation

IMA calculates and stores cryptographic hashes of files, detecting unauthorized modifications.

Report an error in this question

OS SecurityHard

Q21. What is Secure Boot?

  1. A.A UEFI feature ensuring only signed and trusted software loads during boot, preventing bootkits✓ Correct
  2. B.A symmetric key data encryption algorithm applied to data protection workflows
  3. C.An automated feature for creating data backups for managing enterprise data resources
  4. D.An option to boot the system more quickly within modern computing environments

Explanation

Secure Boot verifies digital signatures of boot software to ensure only trusted code runs during startup.

Report an error in this question

OS SecurityMedium

Q22. What is sandboxing in OS security?

  1. A.Playing in a physical sandbox recreation area across computing environments
  2. B.A type of data encryption applied to data protection workflows
  3. C.Running applications in an isolated environment to limit their access to system resources✓ Correct
  4. D.A next-generation firewall for filtering network traffic flows

Explanation

Sandboxing isolates running programs in a controlled environment with restricted access to system resources.

Report an error in this question

OS SecurityHard

Q23. What is Trusted Platform Module (TPM)?

  1. A.A wired network interface adapter for connectivity used in enterprise computing environments
  2. B.A next-generation firewall for filtering network traffic flows
  3. C.A hardware-based security chip that provides cryptographic functions and secure key storage✓ Correct
  4. D.A type of volatile random access memory module used in enterprise computing environments

Explanation

TPM is a dedicated hardware chip that generates and securely stores cryptographic keys.

Report an error in this question

OS SecurityHard

Q24. What is the difference between Type 1 and Type 2 hypervisors in security?

  1. A.Type 1 runs directly on hardware providing better isolation, Type 2 runs on a host OS adding extra attack surface✓ Correct
  2. B.Type 1 is software-only without any additional considerations needed
  3. C.Type 2 is more secure within enterprise security environments across computing environments
  4. D.No security difference in any deployment scenario or context or notable impact in any deployment scenario

Explanation

Type 1 bare-metal hypervisors provide stronger isolation. Type 2 runs atop a host OS, inheriting its vulnerabilities.

Report an error in this question

OS SecurityHard

Q25. What is namespace isolation in Linux containers?

  1. A.Naming convention for files within enterprise security environments in security contexts
  2. B.A kernel feature providing isolated views of system resources for processes, forming the basis of container security✓ Correct
  3. C.A DNS configuration within modern computing environments for security management
  4. D.A programming concept used in enterprise computing environments for security management

Explanation

Linux namespaces isolate processes by giving them independent views of system resources (PID, network, mount, user).

Report an error in this question

OS SecurityHard

Q26. What is a race condition vulnerability in OS security?

  1. A.A concurrency competition between processes commonly found within modern computing environments
  2. B.A type of scheduling algorithm used to manage processes within enterprise computing environments
  3. C.A flaw where the outcome depends on timing, allowing exploitation of the window between check and use✓ Correct
  4. D.A fast parallel processing technique used within enterprise computing environments for tasks

Explanation

A race condition (TOCTOU) occurs when a program checks a condition and an attacker changes it before the action.

Report an error in this question

OS SecurityMedium

Q27. What is the purpose of audit logging in an OS?

  1. A.To record security-relevant events for monitoring, investigation, and compliance✓ Correct
  2. B.To identify and remove obsolete system files and management
  3. C.To add computational overhead slowing the system and management
  4. D.To reduce data sizes through compression methods and management

Explanation

Audit logging records security-relevant events for security monitoring and forensic investigation.

Report an error in this question

OS SecurityHard

Q28. What is credential guard in Windows 10/11?

  1. A.A standard software application used for routine enterprise computing operation tasks
  2. B.A user account type with specifically assigned and managed access permissions
  3. C.A feature using virtualization-based security to isolate and protect credential secrets from theft✓ Correct
  4. D.A next-generation firewall solution for filtering and monitoring network traffic

Explanation

Credential Guard uses hardware virtualization to isolate credential secrets, preventing credential theft attacks.

Report an error in this question

OS SecurityHard

Q29. What is a kernel-level rootkit?

  1. A.A next-generation firewall security appliance deployed across enterprise environments
  2. B.A legitimate administrative system utility tool used in enterprise computing environments
  3. C.A standard user-space application for management within the identity management system
  4. D.Malware that operates at the kernel level, hiding its presence and having unrestricted system access✓ Correct

Explanation

A kernel-level rootkit modifies the OS kernel, giving it the highest privilege level and making it extremely difficult to detect.

Report an error in this question

OS SecurityHard

Q30. What is eBPF and how is it used in OS security?

  1. A.A standard network communication protocol for data transmission
  2. B.A symmetric key data encryption algorithm applied to data protection workflows
  3. C.An in-kernel virtual machine allowing sandboxed programs for security monitoring without modifying kernel source✓ Correct
  4. D.A file format used for structured data storage for managing enterprise data resources

Explanation

eBPF enables running sandboxed programs in the Linux kernel for security monitoring, tracing, and enforcement.

Report an error in this question

Ready to test yourself on OS Security?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start OS Security Quiz