"Many security controls are ineffective or can be overridden if an attacker gets physical access to your hosts, especially if attackers are able to reboot those hosts. For example, by rebooting your Red Hat Enterprise Linux server, an attacker can sign into single user mode and change your root password--achieving a total compromise of your server.
"In this tip, I will look at how you can secure your GRUB boot loader with a password that will prevent unauthorized access to your hosts after a reboot..."