easyMultiple Choice
XK0-006 Practice Question: A Linux administrator discovers that a user's…
A Linux administrator discovers that a user's home directory contains a file with setuid bit set, owned by root. The file is not part of any authorized software. What is the most appropriate immediate action?
⚠ Common exam trap
Many exam-takers choose deletion (Option B) as the 'obvious' fix, overlooking the forensic value of the file and the fact that removing the setuid bit is a less destructive and equally effective containment measure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the setuid bit with 'chmod u-s <file>'
The immediate priority is to neutralize the unauthorized setuid root binary, which poses a privilege escalation risk. Removing the setuid bit with 'chmod u-s' disables the ability for any user to execute the file with root privileges, containing the threat without destroying evidence that may be needed for forensic analysis. This aligns with security best practices of preserving artifacts while mitigating active risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move the file to /tmp for further analysis
Why it's wrong here
Moving the file to /tmp relocates it to a world-writable, often noexec-mounted directory without stripping the setuid bit, so the privilege-escalation vector persists. It is tempting as quarantine for later analysis, which suits non-executable artefacts rather than a live root-owned setuid binary.
- ✗
Delete the file immediately to remove the threat
Why it's wrong here
Deleting destroys forensic evidence and may breach incident-handling obligations; the immediate priority is containment, which removing the setuid bit achieves while preserving the file. Deletion is tempting as swift threat removal, and would suit disposable malware with no investigative or legal value.
- ✗
Change the file owner to the user with 'chown user:user <file>'
Why it's wrong here
Changing ownership to the user leaves the setuid bit intact, so the binary still executes with that owner's privileges and the escalation path remains. It is tempting as a tidy-up of an odd ownership, which would suit a legitimate file mis-owned during a restore rather than an unauthorised setuid binary.
- ✓
Remove the setuid bit with 'chmod u-s <file>'
Why this is correct
Removing the setuid bit with chmod u-s immediately neutralises the privilege-escalation risk, since the root-owned binary would otherwise execute with root privileges. This is the fastest containment action for an unauthorised setuid file in a user's home directory.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
chmod
chmod is a command in Linux and Unix-like operating systems used to change the permissions (read, write, execute) of a file or directory.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.