XK0-006 Troubleshooting Practice Question
A user reports that a shell script fails with a 'Permission denied' error when executed, even though the file has the execute bit set for the owner. The administrator runs `ls -l script.sh` and sees `-rwxr-xr-x`. Which command should the administrator use to determine whether the filesystem is mounted with the `noexec` option?
⚠ Common exam trap
The trap here is focusing on file permissions or attributes when the execute bit is already set, overlooking that a `noexec` mount option can block execution independently of file mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
mount | grep noexec
A filesystem mounted with `noexec` prohibits execution of binaries and scripts regardless of file permissions. Checking the mount options with `mount | grep noexec` directly confirms whether this is the cause. Other commands inspect file attributes, ACLs, or metadata, none of which can reveal a filesystem-level execution restriction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
lsattr script.sh
Why it's wrong here
`lsattr` displays extended file attributes such as immutable or append-only flags. While an immutable attribute could prevent modification, it does not block execution. The `noexec` mount option is a filesystem-level setting, not a file attribute, so `lsattr` cannot detect it. The administrator would see normal attributes and remain unaware of the mount option causing the failure.
- ✗
getfacl script.sh
Why it's wrong here
`getfacl` shows POSIX access control lists for a file, detailing user and group permissions beyond the standard mode bits. The scenario already shows the owner has execute permission, and ACLs would not override a `noexec` mount. This command is useful for fine-grained permission issues but cannot reveal filesystem mount options, so it would not explain the execution failure.
- ✓
mount | grep noexec
Why this is correct
`mount | grep noexec` lists mounted filesystems and filters for the `noexec` mount option. If the filesystem containing the script is mounted with `noexec`, execution is blocked regardless of file permissions. This command directly reveals whether that option is active, explaining the 'Permission denied' error despite the execute bit being set.
- ✗
stat script.sh
Why it's wrong here
`stat` displays file metadata including size, inode, and timestamps, but not filesystem mount options. It cannot indicate whether the underlying filesystem is mounted with `noexec`. While useful for checking permissions and ownership, it would show the execute bits already known to be set, providing no insight into why execution is denied at the filesystem level.
Go deeper
Related to this question
Learn chapter
File Transfer and Remote Access
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Shell
A shell is a computer program that provides a user interface to access an operating system's services, typically by accepting text commands.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.