GPEN Domain Escalation and Persistence Practice Question
When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?
⚠ Common exam trap
Candidates often think SUID files are inherently malicious. They fail to understand that SUID is a legitimate feature that only becomes a security risk when applied to user-writable, root-owned files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It permits the file to execute with the owner's privileges.
The SUID (Set User ID) bit allows a file to execute with the permissions of the file owner rather than the user executing it. If an attacker identifies a SUID file owned by root, they can potentially manipulate the execution flow to gain a root shell. This is a primary target for privilege escalation, as it permits users to circumvent standard permission constraints during execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It forces the file to run within a restricted sandbox environment.
Why it's wrong here
SUID does not provide sandboxing; rather, it elevates the execution context. Sandboxing is a security control used to isolate processes, whereas SUID is a legacy permission mechanism that explicitly grants higher privileges to the process during execution, which is the opposite of the restricted goal of sandboxing.
- ✓
It permits the file to execute with the owner's privileges.
Why this is correct
When the SUID bit is set, the process runs as the owner of the file. If that owner is root, the process runs with root privileges. This behavior is intentional for specific system binaries, but it creates a vulnerability if the binary can be abused to perform unintended actions.
- ✗
It enables the file to be readable by all users on the system.
Why it's wrong here
SUID affects execution privileges, not file system read permissions. Read permissions are governed by the standard rwx bits for owner, group, and others. The SUID bit specifically modifies the process's effective user ID upon execution and has no direct impact on the file's static read permission settings.
- ✗
It automatically encrypts the file contents at rest.
Why it's wrong here
The SUID bit is a permission attribute, not a cryptographic control. It is entirely unrelated to data encryption or the security of file contents while stored on disk. Encryption is handled by separate filesystem or application-level tools, and SUID remains strictly a function of the Linux permission model.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.