Courseiva
GNU and Unix Commands →hardMultiple Choice

LPIC-1 GNU and Unix Commands Practice Question

An administrator is examining a file with 'ls -l' and sees the permission string '-rwSr--r--' on an executable owned by root. What does the capital S in the owner execute position indicate?

⚠ Common exam trap

The trap here is reading the capital S as an ordinary permission or as an ACL marker instead of recognizing it as a special bit paired with a missing execute bit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The set-user-ID bit is set, but the owner execute bit is not set.

The execute slot for each permission class also encodes a special bit. For the owner it is set-user-ID, shown as s when execute is also granted and as S when execute is withheld. Seeing '-rwSr--r--' therefore means setuid is set but the owner cannot execute the file, which is an unusual and often ineffective configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file has an extended ACL entry that grants the owner additional rights.

    Why it's wrong here

    Extended ACLs are indicated by a plus sign appended to the permission string, such as '-rwSr--r--+', not by the capital S itself. The S character specifically encodes a setuid or setgid bit without execute. This file would need a trailing plus to signal an ACL.

  • ✓

    The set-user-ID bit is set, but the owner execute bit is not set.

    Why this is correct

    In the permission string, the owner execute position carries the set-user-ID flag. A lowercase s means both the setuid bit and execute are present, while a capital S means setuid is set but the underlying execute bit is absent. Here the capital S confirms exactly that combination on a root-owned executable.

  • ✗

    The sticky bit is set, and it prevents other users from deleting the file.

    Why it's wrong here

    The sticky bit occupies the other-execute position and is shown as a capital T when execute is absent. On directories it restricts deletion to owners, but on files its modern meaning is largely historical. Its position in the string differs from the owner execute slot shown here.

  • ✗

    The set-group-ID bit is set, but the group execute bit is not set.

    Why it's wrong here

    The set-group-ID flag appears in the group execute position of the permission string, not the owner position. A capital S there would indicate setgid without group execute. In this scenario the capital S is in the owner field, so it refers to set-user-ID, not set-group-ID.

About these practice questions

One of 402 original LPIC-1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official LPI exam blueprint

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.