Courseiva
easyMultiple Choice

XK0-006 Practice Question: Based on the exhibit, what best describes the…

Exhibit

Refer to the exhibit.
ls -la /usr/bin/passwd
-rwsr-xr-x 1 root root 68208 Apr  1  2024 /usr/bin/passwd

Based on the exhibit, what best describes the security implication?

⚠ Common exam trap

CompTIA often tests the distinction between SUID, SGID, and sticky bits by presenting a file listing with an 's' in the owner's execute position and expecting candidates to recognize it as SUID, not confusing it with SGID (which would be in the group position) or the sticky bit (which would be a 't' in the others position).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SUID bit is set, allowing users to run passwd with root privileges to change their own password.

The SUID (Set User ID) bit is set on the /usr/bin/passwd file, as indicated by the 's' in the owner's execute position (e.g., -rwsr-xr-x). This allows any user to run the passwd command with the effective UID of the file owner (root), enabling them to change their own password by writing to /etc/shadow, which is otherwise only writable by root. This is a standard security mechanism, not a vulnerability, as the passwd binary is carefully designed to only allow password changes for the invoking user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SUID bit is set, allowing users to run passwd with root privileges to change their own password.

    Why this is correct

    The SUID bit on /usr/bin/passwd makes the process run with the file owner's effective UID, root, so ordinary users can update /etc/shadow. The binary restricts them to changing only their own password, which is the intended privilege escalation.

  • ✗

    The file is world-writable.

    Why it's wrong here

    World-writable permissions let any user modify or replace the file's contents, but the exhibit's security implication concerns the SUID/SGID privilege bits, not write access. It is tempting because world-writable files are a genuine risk, and it would be correct if the permissions showed the final write bit set for others.

  • ✗

    The SGID bit is set, allowing users to run passwd with group root.

    Why it's wrong here

    The SGID bit on an executable makes it run with the file's group, not root's group; passwd's privilege comes from its SUID root bit, which sets the effective user ID. It is tempting because SGID does confer elevated group rights, and it would be correct for a shared directory or a group-privileged binary.

  • ✗

    The sticky bit is set, preventing deletion of the file.

    Why it's wrong here

    The sticky bit on a directory restricts deletion of files to their owners; on a file it is largely obsolete and does not prevent deletion. It is tempting because it genuinely governs deletion rights, but only within shared directories such as /tmp, not for the file permissions shown in the exhibit.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.