GSEC Linux Security and Hardening Practice Question
A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?
⚠ Common exam trap
The trap here is assuming that noexec is the only way to prevent execution and that nosuid blocks all execution, when nosuid only affects setuid/setgid bits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Leave /home mounted without 'noexec' and instead enforce execution control through SELinux booleans or AppArmor profiles that restrict which binaries the scheduled process may run.
The scenario requires balancing operational need with hardening. Mount options like noexec and nosuid are valuable for directories that should never host executables, but /home may legitimately need to run scripts. Applying mandatory access control lets specific processes execute approved files while blocking everything else, preserving security without breaking the developer's scheduled process. A blanket noexec on /home is too restrictive, and moving execution to world-writable temporary directories undermines the server's defenses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the 'noexec' option from /tmp and /var/tmp so the developer can move scripts there and execute them, keeping /home locked down.
Why it's wrong here
Removing noexec from /tmp and /var/tmp weakens the server's hardening posture by allowing execution from world-writable directories, which is a common malware staging ground. This trades a strong control for a weaker one and does not satisfy the requirement to keep /home secure while enabling legitimate script execution.
- ✗
Add the 'nosuid' option to /home only, because nosuid prevents all executable files from running and resolves the developer's concern.
Why it's wrong here
The nosuid mount option prevents set-user-ID and set-group-ID bits from taking effect; it does not stop ordinary executable files from running. Therefore adding nosuid to /home would not address a developer's need to run scripts and would not stop script execution, making this option both ineffective and based on a misunderstanding.
- ✗
Remount /home with the 'noexec' option and require the developer to store and execute scripts from /var/tmp instead.
Why it's wrong here
Remounting /home with noexec would prevent execution of scripts directly from /home, but directing the developer to /var/tmp is poor practice because /var/tmp is world-writable and often allows execution, increasing the attack surface. This does not securely resolve the need and may introduce new risks.
- ✓
Leave /home mounted without 'noexec' and instead enforce execution control through SELinux booleans or AppArmor profiles that restrict which binaries the scheduled process may run.
Why this is correct
When legitimate scripts must execute from /home, using mandatory access control such as SELinux booleans or AppArmor profiles restricts execution to approved binaries and paths without breaking the developer's workflow. This maintains defense in depth while allowing required functionality, unlike blunt mount options that would block all execution.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.