Courseiva
Linux Fundamentals →hardMultiple Choice

GSEC Linux Fundamentals Practice Question

A Linux server has the setuid bit set on /usr/bin/passwd. A security engineer notices that a custom binary /opt/tools/backup_tool also has the setuid bit set and is owned by root. The engineer wants to determine whether executing backup_tool will run with root privileges regardless of which user invokes it. Which of the following is the most accurate statement about how the setuid bit affects process credentials on Linux?

⚠ Common exam trap

The trap here is believing that setuid changes the real UID as well, when in fact it only changes the effective UID and saved set-user-ID, leaving the real UID intact for accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process runs with the effective UID of the file owner, but the real UID remains that of the invoking user, and the saved set-user-ID is set to the file owner's UID.

Executing a setuid binary causes the kernel to set the process's effective UID to the file owner's UID while preserving the real UID of the invoking user. The saved set-user-ID is also set to the file owner's UID, which lets the program temporarily drop and reacquire elevated privileges. This mechanism is why setuid root binaries are high-value targets: any vulnerability in backup_tool could yield root-level access to an unprivileged attacker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process runs with the effective UID of the file owner only if the binary is also executable by the invoking user; otherwise the kernel silently falls back to the invoking user's UID.

    Why it's wrong here

    Execute permission is required for the binary to run at all, but if the user lacks execute permission the kernel returns EACCES and does not run the program. There is no silent fallback to the invoking user's UID. When execute permission is present and the setuid bit is honored, the effective UID becomes the file owner's UID as usual.

  • ✗

    The setuid bit is ignored on Linux unless the filesystem is mounted with the suid option, so the behavior depends entirely on the mount options of the filesystem holding the binary.

    Why it's wrong here

    While the suid mount option controls whether setuid bits are honored, the question asks how the bit affects process credentials when it is honored. On a normal filesystem with suid enabled (the default for most local filesystems), the kernel does apply the credential change described. Saying the bit is ignored by default misstates the Linux behavior and would incorrectly dismiss the security risk.

  • ✓

    The process runs with the effective UID of the file owner, but the real UID remains that of the invoking user, and the saved set-user-ID is set to the file owner's UID.

    Why this is correct

    When a setuid program is executed, the kernel sets the process's effective UID to the file owner's UID, while the real UID stays as the invoking user's UID. The saved set-user-ID is also set to the file owner's UID, allowing the process to drop and later regain the effective privilege. This is exactly how /usr/bin/passwd can write to /etc/shadow while a normal user runs it.

  • ✗

    The process runs with the real UID, effective UID, and saved set-user-ID all set to the file owner's UID, so the invoking user's identity is completely lost to the kernel.

    Why it's wrong here

    Only the effective UID and saved set-user-ID are changed to the file owner; the real UID remains that of the invoking user. If all three were overwritten, the process could never permanently drop privileges back to the original user, and audit trails based on the real UID would be broken. The kernel preserves the real UID specifically to support privilege dropping and accountability.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.