XK0-006 Security Practice Question
A compliance auditor requires that a Linux server's /home directory be mounted with options that prevent users from executing setuid binaries stored there and from creating device files. The administrator is editing /etc/fstab for the /home entry. Which TWO mount options should be added to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is reaching for noexec when the requirement is specifically to block setuid execution, since noexec is broader and does not cover device files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nosuid
The nosuid option blocks execution of setuid and setgid binaries, and nodev blocks the use of device files on the filesystem. Together they harden /home against privilege escalation and device-based attacks without preventing normal file storage. noexec, noatime, and ro either do not target the stated risks or impose excessive functional restrictions that the auditor did not request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
noatime
Why it's wrong here
noatime disables updates to the file access time on reads, which improves performance and reduces disk writes. It has no security effect on setuid execution or device file creation. While useful for busy filesystems, it does not satisfy either of the auditor's requirements and would be selected only by confusing performance tuning with security hardening.
- ✗
ro
Why it's wrong here
Mounting /home read-only would prevent users from writing files at all, which blocks creating device files but also breaks normal home directory use such as saving documents or shell history. It does not specifically stop setuid execution on existing files and is far too disruptive. It is not the intended security control for these requirements.
- ✓
nosuid
Why this is correct
The nosuid mount option prevents the execution of setuid and setgid programs on that filesystem. Because the requirement is to stop users from running setuid binaries from /home, this option directly satisfies it. It is a standard hardening measure for user-writable directories and works at the kernel mount level without affecting file permissions.
- ✓
nodev
Why this is correct
The nodev mount option prevents the interpretation of block and character special device files on that filesystem. Since the requirement is to stop users from creating usable device files in /home, nodev directly meets it by making any device node created there non-functional. It is a common hardening option for user home directories.
- ✗
noexec
Why it's wrong here
noexec prevents execution of any binary on the filesystem, not just setuid binaries. While it would block setuid execution, it is broader than required and would also stop legitimate user scripts and programs, potentially breaking applications. It does not address device file creation, so it is not the precise answer for the stated requirements.
Go deeper
Related to this question
Learn chapter
Installing Linux and Package Management
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
fstab
fstab is a system configuration file in Linux that defines how and where storage devices and partitions are mounted at boot time.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.