Courseiva
hardMultiple Choice

220-1202 Practice Question: A technician is investigating a privilege…

A technician is investigating a privilege escalation vulnerability. They need to list all files in /usr/bin that have the SUID or SGID bit set and are owned by root. Which single command will achieve this?

⚠ Common exam trap

CompTIA often tests the distinction between `-perm -mode` (all bits must match) and `-perm /mode` (any bit can match), and candidates frequently confuse the minus sign with the forward slash, leading them to pick Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

find /usr/bin -user root -perm /6000

The `find` command with `-perm /6000` matches files where either the SUID (4000) or SGID (2000) bit is set, combined with `-user root` to restrict results to files owned by root. The `/` prefix in the permission mask tells `find` to match any of the specified bits, making it the precise single command for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    find /usr/bin -user root -perm -6000

    Why it's wrong here

    The -perm -6000 form requires both SUID and SGID bits simultaneously, missing files with only one bit set. It is tempting because 6000 looks like the combined mask, and it would be correct when searching specifically for files carrying both bits at once.

  • ✗

    find /usr/bin -user root -perm 4000 -o -perm 2000

    Why it's wrong here

    This is syntactically incorrect; the -o operator needs to be properly grouped with parentheses, and it does not combine the conditions correctly.

  • ✗

    ls -la /usr/bin | grep '^...s'

    Why it's wrong here

    This uses grep to find SUID files but does not filter by owner root, and it does not capture SGID files correctly.

  • ✓

    find /usr/bin -user root -perm /6000

    Why this is correct

    The -perm /6000 test matches files with either the SUID (4000) or SGID (2000) bit set, since the leading slash means any of those bits. Combined with -user root, it lists exactly the root-owned binaries in /usr/bin carrying either privilege bit.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.