Courseiva
Linux Fundamentals →mediumMultiple Choice

GSEC Linux Fundamentals Practice Question

A security administrator needs to ensure that a newly created script, 'cleanup.sh', can only be executed by the file owner, while preventing any other users from reading or writing the file. Which command achieves this configuration?

⚠ Common exam trap

Candidates often mix up octal permission positions or confuse read/write/execute values, mistakenly selecting 777 or 007 because they fail to map the owner-only requirement properly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

chmod 700 cleanup.sh

The chmod command with the octal value 700 applies read, write, and execute permissions exclusively to the owner (7), while setting no permissions for the group (0) and others (0). This follows the principle of least privilege by isolating the script's execution to the authorized user. Restricting access is critical in Linux security to prevent unauthorized execution of potentially sensitive maintenance utilities by standard users or attackers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    chmod 777 cleanup.sh

    Why it's wrong here

    This setting grants full read, write, and execute permissions to all users on the system. This creates a severe security vulnerability, allowing any user to modify or execute the script, which could lead to unauthorized system changes or privilege escalation if the script is executed by a high-privileged user.

  • ✗

    chmod 755 cleanup.sh

    Why it's wrong here

    This configuration allows the owner full access while permitting all other users to read and execute the file. In a security context, this is overly permissive because it allows any user to inspect the script's logic and potentially identify weaknesses or sensitive data processed during the cleanup operation.

  • ✓

    chmod 700 cleanup.sh

    Why this is correct

    The 700 octal mode provides full control to the owner (rwx) and explicitly denies all access to group and other users. This ensures that only the file owner can interact with the script, effectively mitigating risks associated with unauthorized execution or inspection of sensitive administrative tasks on the Linux system.

  • ✗

    chmod 600 cleanup.sh

    Why it's wrong here

    This setting allows the owner to read and write the file but removes the execute permission. Without the execute bit, the user cannot run the script as a command, rendering it useless for its intended purpose of an automated cleanup task while still maintaining secure file access controls.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.