GSEC Linux Security and Hardening Practice Question
A security analyst is hardening a fleet of Linux servers and wants to reduce the risk of privilege escalation through file capabilities and setuid binaries. The analyst plans to audit and restrict these mechanisms. Which two actions best support this goal? (Choose two.)
⚠ Common exam trap
The trap here is choosing broad, destructive controls like noexec on all filesystems instead of targeted enumeration and removal of unnecessary privilege bits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Search for setuid binaries with 'find / -perm -4000 -type f' and remove the setuid bit from any binary not strictly required.
Reducing privilege escalation risk from setuid binaries and file capabilities requires discovering and minimizing them. Recursively enumerating capabilities with getcap and locating setuid files with find allows the analyst to identify unnecessary privilege grants and remove them. Blanket measures such as noexec mounts or immutable attributes are overly broad and break systems, while disabling sudo and using direct root logon weakens accountability instead of strengthening security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mount all filesystems with the 'noexec' option to prevent any binary from running.
Why it's wrong here
Mounting all filesystems noexec would prevent legitimate system and application binaries from executing, breaking the servers. It is an overly broad measure that does not specifically target setuid or capability-based escalation and would cause severe operational failures. Hardening should be targeted, not applied indiscriminately across every mount point.
- ✗
Set the immutable attribute on all files owned by root using 'chattr +i' recursively.
Why it's wrong here
Applying the immutable attribute recursively to all root-owned files would prevent essential updates, logging, and normal system operation, effectively rendering the system unmanageable. It does not specifically address setuid or file capabilities and would cause widespread breakage. This is not a viable hardening technique for the stated goal.
- ✓
Search for setuid binaries with 'find / -perm -4000 -type f' and remove the setuid bit from any binary not strictly required.
Why this is correct
The find command with -perm -4000 locates files with the setuid bit set, which run with the file owner's privileges, often root. Removing the setuid bit from binaries that do not require it eliminates a common privilege escalation vector while preserving necessary functionality. This is a core hardening action for setuid auditing.
- ✗
Disable the sudo service and require all administrators to log in directly as root for administrative tasks.
Why it's wrong here
Disabling sudo and forcing direct root logon increases risk by removing accountability and audit trails, and it does not address setuid binaries or file capabilities at all. Direct root logon makes privilege escalation easier to hide and contradicts least privilege principles. This action works against the stated hardening objective rather than supporting it.
- ✓
Run 'getcap -r /' to enumerate files with capabilities and review each for necessity.
Why this is correct
getcap -r / recursively scans the filesystem for files carrying POSIX capabilities, which can grant privileges such as cap_setuid or cap_net_raw without the setuid bit. Enumerating them allows the analyst to identify and remove unnecessary capabilities, directly reducing privilege escalation risk. This is a standard auditing step for capability-based hardening.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.