mediumMultiple Choice
XK0-006 Practice Question: A technician notices that a user can execute a…
A technician notices that a user can execute a binary with elevated privileges even though the user is not in the sudoers file. The binary has the SUID bit set. Which command would remove the SUID bit from the binary?
⚠ Common exam trap
Candidates might think that using a numeric mode like 0755 is required because it 'resets permissions safely,' but the question specifically asks only to remove the SUID bit. Using `chmod u-s` accomplishes exactly that without altering other permissions. The exam expects the direct method, not an overhanded numeric reset.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chmod u-s /path/to/binary
`chmod u-s /path/to/binary` is the direct command to remove the SUID bit from the file. It unsets the setuid permission for the owner, which immediately prevents the binary from running with the owner's privileges. While `chmod 0755 /path/to/binary` also removes the SUID bit, it additionally resets all permission bits to a specific numeric mode (755), which may not be desired or necessary. The question asks only for removing the SUID bit, so `chmod u-s` is the most precise and correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
chmod u-s /path/to/binary
Why this is correct
`chmod u-s /path/to/binary` clears only the owner's SUID bit, directly satisfying the stem's requirement to strip elevated execution rights from a binary whose owner lacks sudoers membership. The `u-s` symbolic mode targets the setuid permission on the user class, leaving group and other bits untouched.
- ✗
chmod g-s /path/to/binary
Why it's wrong here
`chmod g-s` clears the setgid bit, which governs group inheritance on execution, not the SUID bit that grants owner-level privilege escalation. It is tempting because `g-s` mirrors the `u-s` syntax, and setgid removal is the right action when a binary improperly inherits a privileged group.
- ✗
chmod o-s /path/to/binary
Why it's wrong here
chmod o-s removes the sticky bit, not the SUID bit, so it is incorrect.
- ✗
chmod 0755 /path/to/binary
Why it's wrong here
Octal 0755 sets rwxr-xr-x, which leaves the owner execute position at 1 rather than 4, so SUID is cleared; however, it also strips group and other write permissions, altering access beyond the SUID removal the task requires. It is tempting as a blanket permission reset.
Go deeper
Related to this question
Learn chapter
File Permissions and Ownership
Key term
SUID
SUID (Set User ID) is a special file permission in Linux that allows a user to run an executable file with the file owner's privileges, typically root, rather than their own.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.